CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3864  CVE-2001-1060  Candidate  phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.  Proposed (20020131)  ACCEPT(1) Cole | MODIFY(2) Frech, Green | NOOP(3) Armstrong, Foat, Wall  Green> Combining similar issues for the same product sounds reasonable | Frech> XF:phpmyadmin-eval-execute-commands(6929)  View
2376  CVE-2000-0800  Candidate  String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.  Proposed (20000921)  ACCEPT(1) Cole | MODIFY(2) Frech, Levy | NOOP(2) Baker, Wall | REJECT(1) Christey  Levy> This is the same as other Linux vendors statd format string problem. | | Reference: BID 1480 | Christey> If this is the same as the other statd format string problems, | then this is a duplicate of CVE-2000-0666. | Frech> XF:linux-rpcstatd-format-overwrite(4939) | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> OK, I agree that this is a dupe of CVE-2000-0666. | Here"s why: | | BUGTRAQ:20000803 SuSE Security: miscellaneous | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96540330329127&w=2 | | One statement says "The SuSE package containing rpc.kstatd | (other vendors named it rpc.statd)... An updated package is | currently being tested."  View
1693  CVE-2000-0115  Candidate  IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.  Proposed (20000208)  ACCEPT(1) Cole | NOOP(1) Baker | REJECT(2) Frech, LeBlanc | REVIEWING(1) Wall  Frech> This reference to NTBugtraq has a message that ends with "Can anyone | reproduce this?", and there are no followups. This makes for a weak | reference. There are also no other references listed for this CAN. | LeBlanc> - no follow-ups, no KB article, no fix | CHANGE> [Frech changed vote from REVIEWING to REJECT]  View
1367  CVE-1999-1387  Candidate  Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.  Proposed (20010912)  ACCEPT(1) Cole | NOOP(1) Foat    View
1471  CVE-1999-1491  Candidate  abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.  Proposed (20010912)  ACCEPT(1) Cole | NOOP(1) Foat    View

Page 655 of 20943, showing 5 records out of 104715 total, starting on record 3271, ending on 3275

Actions