CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3864 | CVE-2001-1060 | Candidate | phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php. | Proposed (20020131) | ACCEPT(1) Cole | MODIFY(2) Frech, Green | NOOP(3) Armstrong, Foat, Wall | Green> Combining similar issues for the same product sounds reasonable | Frech> XF:phpmyadmin-eval-execute-commands(6929) | View |
2376 | CVE-2000-0800 | Candidate | String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges. | Proposed (20000921) | ACCEPT(1) Cole | MODIFY(2) Frech, Levy | NOOP(2) Baker, Wall | REJECT(1) Christey | Levy> This is the same as other Linux vendors statd format string problem. | | Reference: BID 1480 | Christey> If this is the same as the other statd format string problems, | then this is a duplicate of CVE-2000-0666. | Frech> XF:linux-rpcstatd-format-overwrite(4939) | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> OK, I agree that this is a dupe of CVE-2000-0666. | Here"s why: | | BUGTRAQ:20000803 SuSE Security: miscellaneous | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96540330329127&w=2 | | One statement says "The SuSE package containing rpc.kstatd | (other vendors named it rpc.statd)... An updated package is | currently being tested." | View |
1693 | CVE-2000-0115 | Candidate | IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. | Proposed (20000208) | ACCEPT(1) Cole | NOOP(1) Baker | REJECT(2) Frech, LeBlanc | REVIEWING(1) Wall | Frech> This reference to NTBugtraq has a message that ends with "Can anyone | reproduce this?", and there are no followups. This makes for a weak | reference. There are also no other references listed for this CAN. | LeBlanc> - no follow-ups, no KB article, no fix | CHANGE> [Frech changed vote from REVIEWING to REJECT] | View |
1367 | CVE-1999-1387 | Candidate | Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25. | Proposed (20010912) | ACCEPT(1) Cole | NOOP(1) Foat | View | |
1471 | CVE-1999-1491 | Candidate | abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program. | Proposed (20010912) | ACCEPT(1) Cole | NOOP(1) Foat | View |
Page 655 of 20943, showing 5 records out of 104715 total, starting on record 3271, ending on 3275