CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4183  CVE-2001-1379  Candidate  The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.  Proposed (20020726)  ACCEPT(4) Armstrong, Baker, Cole, Cox | NOOP(2) Foat, Wall    View
3696  CVE-2001-0890  Candidate  Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.  Proposed (20020726)  ACCEPT(5) Armstrong, Baker, Cole, Cox, Wall | NOOP(1) Foat    View
5011  CVE-2002-0620  Candidate  Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.  Proposed (20020726)  ACCEPT(4) Baker, Cole, Foat, Wall | NOOP(2) Christey, Cox  Christey> XF:mscs-profile-service-bo(9423) | URL:http://www.iss.net/security_center/static/9423.php  View
5034  CVE-2002-0644  Candidate  Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.  Proposed (20020726)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> BUGTRAQ:20020725 SQL Server 2000 Buffer Overflows and SQL Inyection vulnerabilities. | URL:http://online.securityfocus.com/archive/1/284382 | XF:mssql-dbcc-bo(9659) | URL:http://www.iss.net/security_center/static/9659.php | Add details to desc. Affected functions are: | (1)ADDEXTENDEDPROC, (2) INDEXFRAG, (3) UPDATEUSAGE, (4) | CHECKCONSTRAINTS, (5) SHOWCONTIG, and (6) CLEANTABLE. | Frech> XF:mssql-dbcc-bo(9659)  View
5035  CVE-2002-0645  Candidate  SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.  Proposed (20020726)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> XF:mssql-replication-sql-injection(9660) | URL:http://www.iss.net/security_center/static/9660.php | BUGTRAQ:20020725 SQL Server 2000 Buffer Overflows and SQL Inyection vulnerabilities. | URL:http://online.securityfocus.com/archive/1/284382 | Mention that the function "sp_MScopyscript" is affected, along | with other functions. | Frech> XF:mssql-replication-sql-injection(9660)  View

Page 87 of 20943, showing 5 records out of 104715 total, starting on record 431, ending on 435

Actions