CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4950 | CVE-2002-0559 | Candidate | Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name. | Proposed (20020611) | ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> ADDREF XF:oracle-appserver-location-bo(8457) | View |
4951 | CVE-2002-0560 | Candidate | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns. | Proposed (20020611) | ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:oracle-appserver-owautil-gain-information(8451) | View |
4954 | CVE-2002-0563 | Candidate | The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes. | Modified (20070207) | ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:oracle-appserver-apache-services(8455) | View |
4842 | CVE-2002-0450 | Candidate | Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe. | Modified (20050707) | ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:webplus-wml-bo(8446) | View |
5270 | CVE-2002-0880 | Candidate | Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2." | Proposed (20020830) | ACCEPT(3) Alderson, Cole, Foat | MODIFY(3) Baker, Frech, Jones | NOOP(2) Armstrong, Cox | Jones> Suggest description removes tool references: "Cisco IP Phone | (VoIP) models 7910, 7940, and 7960 allow remote | attackers to cause a denial of service (crash) via a flood of malformed IP | packets." The tools are just generators of specific malformed packets and | don"t actually represent vulnerabilities; the vulnerability is in the | ability of the Cisco device IP stack to handle various malformed packets. | Cisco description indicates that the solution was to improve the devices" | ability to handle high rates of traffic (not to repair specific packet | handling code in the stack). This suggests a single CVE entry (vice | multiple entries if the stack had a set of different vulnerabilities). | Baker> I agree the description should be changed to describe the problem as failure to handle malformed IP packets | Frech> XF:cisco-ipphone-multiple-dos(9145) | View |
Page 891 of 20943, showing 5 records out of 104715 total, starting on record 4451, ending on 4455