CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1606  CVE-2000-0028  Candidate  Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.  Modified (20000626-01)  ACCEPT(2) Armstrong, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Baker | RECAST(1) LeBlanc | REVIEWING(1) Christey  Frech> XF:ie-navigateandfind | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0266 may | also be a variant. | Levy> BID 887 | LeBlanc> duplicate  View
798  CVE-1999-0818  Candidate  Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.  Proposed (19991208)  ACCEPT(2) Armstrong, Stracener | MODIFY(4) Cole, Dik, Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey  Cole> This can cause code to be executed. | Frech> XF:sol-kcms-conf-netpath-bo | Dik> the bug has nothing to do with kcms_configure; it"s a bug | in libnsl.so. All set-uid executables that trigger this code path are | vulnerable. Sun bug 4295834; fixed in Solaris 8. | Prosser> Okay, I am confused. Based on Casper"s comments and checking | on the Sun patch site, I found the 4295834 bug(4295834 NETPATH security | problem in libnsl) fixed in SunOS 5.4, Patch 101974-37(x86) 101973 (sparc). | Multiple libnsl vulnerabilities was first reported in an 98 Sun Bulletin | #00172 for 5.4 up through 2.6. Was this NETPATH a problem that resurfaced | in 7 (looks like in 5.4 as well) and was fixed in 8? | Christey> Need to dig up my offline email on this. | Christey> May be a duplicate of CVE-1999-0321, whose sole reference | (XF:sun-kcms-configure-bo) no longer exists. Also examine | BID:452 and | BUGTRAQ:19981223 Merry Christmas to Sun! (Was: L0pht NFR N-Code | Modules Updated) | | which are the same as XF:sol-kcms-conf-p-bo(3652), which could | be the new name for XF:sun-kcms-configure-bo.  View
8774  CVE-2004-0346  Candidate  Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.  Proposed (20040318)  ACCEPT(2) Armstrong, Stracener | NOOP(3) Cole, Cox, Wall    View
8768  CVE-2004-0340  Candidate  Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.  Modified (20050719)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View
8769  CVE-2004-0341  Candidate  WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.  Modified (20050719)  ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox    View

Page 767 of 20943, showing 5 records out of 104715 total, starting on record 3831, ending on 3835

Actions