CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1765 | CVE-2000-0187 | Candidate | EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(6) Baker, Blake, Christey, Cole, LeBlanc, Wall | Christey> Since EZShopper is written in Perl, there is strong evidence | that both the .. and metacharacter attack probably go | through the same insecure open() call. (Perl"s open can | either read a regular file, or read piped output from | a command that is specified to the open). | Frech> XF:ezshopper-loadpage-cgi(4044) | View |
1766 | CVE-2000-0188 | Candidate | EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(6) Baker, Blake, Christey, Cole, LeBlanc, Wall | Christey> The exploit is different than CVE-2000-0187 by going through | a different field in a different script, so maybe this should | be kept separate, even though it"s probably another open() | call problem. | Frech> XF:ezshopper-search-cgi(4045) | View |
2124 | CVE-2000-0547 | Candidate | Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(2) Cox, Frech | NOOP(2) LeBlanc, Wall | Frech> XF:kerberos-localrealm-bo(4657) | I question whether BID-1338 is appropriate here. | Cox> ADDREF REDHAT:RHSA-2000:031 | View |
2123 | CVE-2000-0546 | Candidate | Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(2) Cox, Frech | NOOP(3) Christey, LeBlanc, Wall | Christey> ADDREF XF:kerberos-lastrealm-bo | Frech> XF:kerberos-lastrealm-bo(4656) | I question whether BID-1338 is appropriate here. | Cox> ADDREF REDHAT:RHSA-2000:031 | View |
2097 | CVE-2000-0520 | Candidate | Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name. | Proposed (20000712) | ACCEPT(2) Levy, Prosser | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall | Christey> ADDREF BUGTRAQ:20000711 MDKSA-2000:018 dump update | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0166.html | Frech> XF:linux-restore-bo(4647) | Prosser> Add Sources: | http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-018.php3?dis=6.0 | http://www.redhat.com/support/errata/RHSA-2000-100.html | View |
Page 887 of 20943, showing 5 records out of 104715 total, starting on record 4431, ending on 4435