CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5299 | CVE-2002-0910 | Candidate | Buffer overflows in netstd 3.07-17 package allows remote DNS servers to execute arbitrary code via a long FQDN reply, as observed in the utilities (1) linux-ftpd, (2) pcnfsd, (3) tftp, (4) traceroute, or (5) from/to. | Proposed (20020830) | ACCEPT(2) Foat, Frech | NOOP(5) Alderson, Armstrong, Cole, Cox, Jones | View | |
5045 | CVE-2002-0655 | Candidate | OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat | Cox> ADDREF:RHSA-2002:163 RHSA-2002:164 RHSA-2002:157 | This issue also affects SSLeay and BSAFE SSL-C | ADDREF: http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL_Products_Security_Bulletin_Aug_8_2002.pdf | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | Christey> I should probably create a separate CAN for the BSAFE issues, | unless there is a codebase relationship. | View |
5301 | CVE-2002-0912 | Candidate | in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote attackers to cause a denial of service, possibly due to a buffer overflow. | Proposed (20020830) | ACCEPT(6) Alderson, Armstrong, Baker, Cole, Frech, Jones | NOOP(2) Cox, Foat | View | |
5302 | CVE-2002-0913 | Candidate | Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View | |
5047 | CVE-2002-0657 | Candidate | Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat | Cox> The majority of the vendor references listed are incorrect, those vendors | did not ship 0.9.7. Each one should be checked for accuracy, those | not shipping 0.9.7 were not affected. | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | View |
Page 69 of 20943, showing 5 records out of 104715 total, starting on record 341, ending on 345