CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2850 | CVE-2001-0029 | Candidate | Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup. | Modified (20020222-01) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Wall, Ziese | Frech> XF:oops-dns-bo(6122) | Christey> This looks like a different overflow than the one described | in the original post at: | http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html | The vendor does acknowledge *that* problem in the 1.5.0 | comments of | http://zipper.paco.net/~igor/oops/ChangeLog | Christey> Vendor fixed this problem between 1.4.22 and 1.5.5, based | on a source code comparison. | CD:SF-LOC says that bugs of the same type, that appear in | different versions, must be SPLIT. Therefore this should | stay separate from CVE-2001-0028. | | Change MISC to CONFIRM. The comments for version 1.5.4 | say "more sprintf/strncpy fixes" and that"s the type of | changes that were made in lib.c, the code that was listed | in the Bugtraq post for this CAN. | View |
5428 | CVE-2002-1040 | Candidate | Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames. | Proposed (20020830) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:aix-dsfweb-scripts-insecure(10390) | View |
5429 | CVE-2002-1041 | Candidate | Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames. | Proposed (20020830) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:aix-smit-panels-insecure(10393) | View |
4978 | CVE-2002-0587 | Candidate | Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters. | Proposed (20020611) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:aolserver-dbproxy-bo(9840) | View |
3335 | CVE-2001-0521 | Candidate | Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document. | Proposed (20010727) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese | REVIEWING(1) Bishop | CHANGE> [Frech changed vote from ACCEPT to MODIFY] | Frech> DELREF:XF:esafe-gateway-bypass-filtering(6580) | ADDREF:XF:content-unicode-bypass-filter(6980) | Baker> Found acknowledgement in the release notes for build 71, that said: | | "15. Fixed a bug that used to cause the SmartStripping mechanism to miss some scripts in HTML pages." | | Release notes are at the following url: | ftp://ftp.ealaddin.com/pub/manuals/ESG/ESG3.x/esg_rn.zip | View |
Page 773 of 20943, showing 5 records out of 104715 total, starting on record 3861, ending on 3865