CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3009 | CVE-2001-0188 | Candidate | GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash. | Proposed (20010309) | ACCEPT(2) Frech, Oliver | NOOP(2) Lawler, Ziese | Oliver> Identified in Hotfix | View |
4737 | CVE-2002-0345 | Candidate | Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServerparams registry key, which could allow an attacker to gain privileges. | Proposed (20020502) | ACCEPT(2) Frech, Prosser | NOOP(4) Cole, Cox, Foat, Wall | Prosser> This was verified and responded to via BugTraq and fixed via | LiveUpdate http://online.securityfocus.com/archive/1/259559 | View |
104 | CVE-1999-0104 | Candidate | A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. | Modified (20090302) | ACCEPT(2) Frech, Wall | REVIEWING(1) Christey | Wall> Another reference is Microsoft Knowledge Base Q179129. | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> MSKB:Q179129 | http://support.microsoft.com/support/kb/articles/q179/1/29.asp | Christey> MSKB:Q179129 | http://support.microsoft.com/support/kb/articles/q179/1/29.asp | Note that the hotfix name is teardrop2, but the keywords | included in the KB article specifically name bonk | (CVE-1999-0258) and boink. | Since teardrop2 was fixed in a slightly different version | (at least in a separate patch) than Teardrop, CD:SF-LOC | suggests keeping them separate. | Christey> Add period to the end of the description. | View |
3389 | CVE-2001-0576 | Candidate | lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the "-u" command line parameter. | Modified (20020225-01) | ACCEPT(2) Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | Bishop> recommend combining as stated in analysis | Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem. | Williams> re: Baker recast - why merge 19 separate vuln issues into one CAN? | View |
3391 | CVE-2001-0578 | Candidate | Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command. | Modified (20020225-01) | ACCEPT(2) Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | Bishop> recommend combining as stated in analysis | Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem. | View |
Page 881 of 20943, showing 5 records out of 104715 total, starting on record 4401, ending on 4405