CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8534  CVE-2004-0106  Candidate  Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.  Modified (20100819)  ACCEPT(3) Armstrong, Baker, Cox | NOOP(2) Christey, Cole | REVIEWING(1) Wall  Christey> CIAC:O-081 | URL:http://www.ciac.org/ciac/bulletins/o-081.shtml | IMMUNIX:IMNX-2004-73-002-01 | URL:http://www.securityfocus.com/advisories/6328 | BID:9655 | URL:http://www.securityfocus.com/bid/9655 | TURBO:TLSA-2004-5 | URL:http://www.turbolinux.com/security/2004/TLSA-2004-5.txt | Christey> SCO:SCOSA-2004.2 | URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt | SCO:SCOSA-2004.3 | URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt  View
3582  CVE-2001-0775  Candidate  Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.  Modified (20050329)  ACCEPT(3) Armstrong, Baker, Foat | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Frech> XF:xloadimage-faces-bo(6821) | Christey> ADDREF RHSA-2001:088 (per Mark Cox of Red Hat)  View
8484  CVE-2004-0056  Candidate  Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Green | NOOP(3) Cole, Cox, Wall    View
1911  CVE-2000-0333  Candidate  tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.  Proposed (20000518)  ACCEPT(3) Armstrong, Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:sniffer-dns-decode-dos  View
580  CVE-1999-0598  Candidate  A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.  Proposed (19990726)  ACCEPT(3) Armstrong, Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey  Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html  View

Page 905 of 20943, showing 5 records out of 104715 total, starting on record 4521, ending on 4525

Actions