CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3733  CVE-2001-0927  Candidate  Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.  Modified (20050309)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:libgtop-format-string(7608) | Christey> BID:3586 | URL:http://www.securityfocus.com/bid/3586 | CONECTIVA:CLA-2002:448 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000448 | MANDRAKE:MDKSA-2001:094 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-094.php3 | DEBIAN:DSA-098 | URL:http://www.debian.org/security/2002/dsa-098  View
5420  CVE-2002-1032  Candidate  Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.  Proposed (20020830)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:kfwebserver-http-header-bo(10461)  View
4935  CVE-2002-0544  Candidate  Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.  Proposed (20020611)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:abyss-unicode-directory-traversal(8805)  View
5022  CVE-2002-0632  Candidate  Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server.  Modified (20060626)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> BID:5448 | URL:http://www.securityfocus.com/bid/5448 | XF:irix-bds-unauth-access(9825) | URL:http://www.iss.net/security_center/static/9825.php | | Change desc to "unknown vulnerability" | Frech> XF:irix-bds-unauth-access(9825)  View
5361  CVE-2002-0973  Candidate  Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.  Modified (20050529)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> BID:5493 | URL:http://online.securityfocus.com/bid/5493 | Frech> XF:freebsd-negative-system-call-bo(9903)  View

Page 896 of 20943, showing 5 records out of 104715 total, starting on record 4476, ending on 4480

Actions