CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4496 | CVE-2002-0102 | Candidate | Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters. | Modified (20050707) | ACCEPT(4) Cole, Foat, Green, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:oracle-appserver-admin-dos(7310) | XF:oracle-appserver-null-dos(7765) | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
4497 | CVE-2002-0103 | Candidate | An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml. | Modified (20050706) | ACCEPT(5) Cole, Foat, Green, Wall, Ziese | MODIFY(1) Frech | Frech> XF:oracle-appserver-webcached-privileges(7766) | XF:oracle-appserver-webcache-password(7768) | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
4498 | CVE-2002-0104 | Candidate | AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View | |
4499 | CVE-2002-0105 | Candidate | CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey | Christey> CALDERA:CSSA-2002-SCO.18 | XF:cde-dt-world-writable(9045) | URL:http://www.iss.net/security_center/static/9045.php | Note: the advisory sort-of implies that world-write | permissions were the key problem, so the fact that a symlink | attack could take place did not necessarily mean that a | symlink following vulnerability really existed, in the sense | that symlink attacks don"t exist in directories that are | not writable by other users (well, without those users | exploiting some *other* vulnerability to allow them to create | the symlink!) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Hmmm... should XF:cde-dt-world-writable(9045) really be added | here? ISS may have "split" between the permissions issue | and the symlink problem. | View |
4500 | CVE-2002-0106 | Candidate | BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View |
Page 900 of 20943, showing 5 records out of 104715 total, starting on record 4496, ending on 4500