CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4950  CVE-2002-0559  Candidate  Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name.  Proposed (20020611)  ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> ADDREF XF:oracle-appserver-location-bo(8457)  View
4951  CVE-2002-0560  Candidate  PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.  Proposed (20020611)  ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:oracle-appserver-owautil-gain-information(8451)  View
4954  CVE-2002-0563  Candidate  The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.  Modified (20070207)  ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:oracle-appserver-apache-services(8455)  View
4842  CVE-2002-0450  Candidate  Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe.  Modified (20050707)  ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:webplus-wml-bo(8446)  View
5270  CVE-2002-0880  Candidate  Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."  Proposed (20020830)  ACCEPT(3) Alderson, Cole, Foat | MODIFY(3) Baker, Frech, Jones | NOOP(2) Armstrong, Cox  Jones> Suggest description removes tool references: "Cisco IP Phone | (VoIP) models 7910, 7940, and 7960 allow remote | attackers to cause a denial of service (crash) via a flood of malformed IP | packets." The tools are just generators of specific malformed packets and | don"t actually represent vulnerabilities; the vulnerability is in the | ability of the Cisco device IP stack to handle various malformed packets. | Cisco description indicates that the solution was to improve the devices" | ability to handle high rates of traffic (not to repair specific packet | handling code in the stack). This suggests a single CVE entry (vice | multiple entries if the stack had a set of different vulnerabilities). | Baker> I agree the description should be changed to describe the problem as failure to handle malformed IP packets | Frech> XF:cisco-ipphone-multiple-dos(9145)  View

Page 891 of 20943, showing 5 records out of 104715 total, starting on record 4451, ending on 4455

Actions