CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3416  CVE-2001-0603  Candidate  Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148.  Proposed (20010727)  ACCEPT(2) Baker, Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Frech> CONFIRM:Lotus SPR #CBRN4QWJUN at | http://www.notes.net/qmrdown.nsf/QMRWelcome  View
3417  CVE-2001-0604  Candidate  Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of "/" characters.  Proposed (20010727)  ACCEPT(2) Baker, Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Frech> CONFIRM:http://www.notes.net/qmrdown.nsf/QMRWelcome; Lotus | does not seem to wax prolific with their DoS explanations. For 5.0.7, | any of these SPR#s have the explanation "Fixed a potential Denial of | Service attack on HTTP.": JCHN4TQS2T, JCHN4RPKC2, JCHN4TQNL8, | JCHN4JQKYQ, JCHN4TGN32.  View
3418  CVE-2001-0605  Candidate  Headlight Software MyGetright prior to 1.0b allows a remote attacker to upload and/or overwrite arbitrary files via a malicious .dld (skins-data) file which contains long strings of random data.  Proposed (20010727)  MODIFY(1) Frech | NOOP(5) Cole, Foat, Prosser, Wall, Ziese | REVIEWING(2) Bishop, Williams  Frech> XF:mygetright-skin-overwrite-file(6155) | In description, product should be "My GetRight" (see | http://www.mygetright.com/get.html) | Prosser> According to Discover"s Bulletin, the vendor, www.mygetright.com acknowledged the problem and fixed it in version 1.0b. However, vendor page makes no mention of this issue.  View
3419  CVE-2001-0606  Candidate  Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.  Modified (20020225-01)  ACCEPT(6) Baker, Bishop, Cole, Wall, Williams, Ziese | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:hp-virtualvault-iws-dos(6110) | CHANGE> [Williams changed vote from REVIEWING to ACCEPT]  View
3420  CVE-2001-0607  Candidate  asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.  Modified (20090302)  ACCEPT(5) Baker, Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Frech> XF:hp-asecure-dos(6212) | Possible duplicate of CVE-2000-0083: HP asecure creates the | Audio Security File audio.sec with insecure permissions, which allows | local users to cause a denial of service or gain additional | privileges. | Williams> Frech - this is not a dupe of CVE-2000-0083. | Christey> While this advisory is vaguely worded, the fact that HP did an | advisory for the other asecure problem (now CVE-2000-0083) | indicates at the very least that this problem occurs in | a different version than CVE-2000-0083, so CD:SF-LOC | suggests a SPLIT. However, the HP advisory says "10.X" | and "11.X" are affected, so who knows what versions they | *really* mean? | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View

Page 684 of 20943, showing 5 records out of 104715 total, starting on record 3416, ending on 3420

Actions