CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1877 | CVE-2000-0299 | Candidate | Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept. | Proposed (20000426) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy | Christey> ADDREF XF:webobjects-post-dos | Frech> XF:webobjects-post-dos | Christey> See http://til.info.apple.com/techinfo.nsf/artnum/n75087 | Document says: | "A request with a large, malformed http header can crash a WOApp" | (Apple reference #2470254) appears to be the acknowledgement needed. | | Is this sufficient acknowledgement? This is dated AUgust 24, | but the initial disclosure occurred on April 4. | Christey> BID:1896 | View |
3098 | CVE-2001-0277 | Candidate | Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request. | Proposed (20010404) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:badblue-ext-dos(6131) | Christey> CONFIRM:http://www.badblue.com/p010219.htm | View |
3124 | CVE-2001-0303 | Candidate | tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file. | Proposed (20010404) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:pi3web-reveal-path(6114) | Christey> This issue was rediscovered a year later, in version 2.0.0. | Since it"s a default configuration problem, it is likely that | the vendor did not fix it. | BUGTRAQ:20020310 Pi3Web/2.0.0 File-Disclosure/Path Disclosure vuln | URL:http://online.securityfocus.com/archive/1/260734 | BID:4261 | XF:pi3web-error-disclosure(8428) | View |
241 | CVE-1999-0242 | Candidate | Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords. | Modified (20000106-01) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Northcutt, Shostack, Wall | REVIEWING(1) Levy | Frech> Ambiguous description: need more detail. Possibly: | XF:linux-pop3d (mktemp() leads to reading e-mail) | Christey> At first glance this might look like CVE-1999-0123 or | CVE-1999-0125, however this particular candidate arises out | of a brief mention of the problem in a larger posting which | discusses CVE-1999-0123 (which may be the same bug as | CVE-1999-0125). See the following phrase in the Bugtraq | post: "one such example of this is in.pop3d" | | However, the original source of this candidate"s description | explicitly mentions shadowed passwords, though it has no | references to help out here. | View |
4767 | CVE-2002-0375 | Candidate | Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter. | Modified (20040818) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:sgdynamo-htname-parameter-xss(9830) | View |
Page 629 of 20943, showing 5 records out of 104715 total, starting on record 3141, ending on 3145