CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1606 | CVE-2000-0028 | Candidate | Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. | Modified (20000626-01) | ACCEPT(2) Armstrong, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Baker | RECAST(1) LeBlanc | REVIEWING(1) Christey | Frech> XF:ie-navigateandfind | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0266 may | also be a variant. | Levy> BID 887 | LeBlanc> duplicate | View |
798 | CVE-1999-0818 | Candidate | Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. | Proposed (19991208) | ACCEPT(2) Armstrong, Stracener | MODIFY(4) Cole, Dik, Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey | Cole> This can cause code to be executed. | Frech> XF:sol-kcms-conf-netpath-bo | Dik> the bug has nothing to do with kcms_configure; it"s a bug | in libnsl.so. All set-uid executables that trigger this code path are | vulnerable. Sun bug 4295834; fixed in Solaris 8. | Prosser> Okay, I am confused. Based on Casper"s comments and checking | on the Sun patch site, I found the 4295834 bug(4295834 NETPATH security | problem in libnsl) fixed in SunOS 5.4, Patch 101974-37(x86) 101973 (sparc). | Multiple libnsl vulnerabilities was first reported in an 98 Sun Bulletin | #00172 for 5.4 up through 2.6. Was this NETPATH a problem that resurfaced | in 7 (looks like in 5.4 as well) and was fixed in 8? | Christey> Need to dig up my offline email on this. | Christey> May be a duplicate of CVE-1999-0321, whose sole reference | (XF:sun-kcms-configure-bo) no longer exists. Also examine | BID:452 and | BUGTRAQ:19981223 Merry Christmas to Sun! (Was: L0pht NFR N-Code | Modules Updated) | | which are the same as XF:sol-kcms-conf-p-bo(3652), which could | be the new name for XF:sun-kcms-configure-bo. | View |
8774 | CVE-2004-0346 | Candidate | Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command. | Proposed (20040318) | ACCEPT(2) Armstrong, Stracener | NOOP(3) Cole, Cox, Wall | View | |
8768 | CVE-2004-0340 | Candidate | Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands. | Modified (20050719) | ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox | View | |
8769 | CVE-2004-0341 | Candidate | WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline. | Modified (20050719) | ACCEPT(2) Armstrong, Wall | NOOP(2) Cole, Cox | View |
Page 767 of 20943, showing 5 records out of 104715 total, starting on record 3831, ending on 3835