CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2850  CVE-2001-0029  Candidate  Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.  Modified (20020222-01)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Wall, Ziese  Frech> XF:oops-dns-bo(6122) | Christey> This looks like a different overflow than the one described | in the original post at: | http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html | The vendor does acknowledge *that* problem in the 1.5.0 | comments of | http://zipper.paco.net/~igor/oops/ChangeLog | Christey> Vendor fixed this problem between 1.4.22 and 1.5.5, based | on a source code comparison. | CD:SF-LOC says that bugs of the same type, that appear in | different versions, must be SPLIT. Therefore this should | stay separate from CVE-2001-0028. | | Change MISC to CONFIRM. The comments for version 1.5.4 | say "more sprintf/strncpy fixes" and that"s the type of | changes that were made in lib.c, the code that was listed | in the Bugtraq post for this CAN.  View
5428  CVE-2002-1040  Candidate  Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.  Proposed (20020830)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:aix-dsfweb-scripts-insecure(10390)  View
5429  CVE-2002-1041  Candidate  Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.  Proposed (20020830)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:aix-smit-panels-insecure(10393)  View
4978  CVE-2002-0587  Candidate  Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.  Proposed (20020611)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:aolserver-dbproxy-bo(9840)  View
3335  CVE-2001-0521  Candidate  Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.  Proposed (20010727)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese | REVIEWING(1) Bishop  CHANGE> [Frech changed vote from ACCEPT to MODIFY] | Frech> DELREF:XF:esafe-gateway-bypass-filtering(6580) | ADDREF:XF:content-unicode-bypass-filter(6980) | Baker> Found acknowledgement in the release notes for build 71, that said: | | "15. Fixed a bug that used to cause the SmartStripping mechanism to miss some scripts in HTML pages." | | Release notes are at the following url: | ftp://ftp.ealaddin.com/pub/manuals/ESG/ESG3.x/esg_rn.zip  View

Page 773 of 20943, showing 5 records out of 104715 total, starting on record 3861, ending on 3865

Actions