CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5229 | CVE-2002-0839 | Candidate | The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard. | Modified (20110830) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | Christey> CONFIRM:http://www.info.apple.com/usen/security/security_updates.html | Cox> Addref: RHSA-2002:251 | Addref: RHSA-2002:248 | Addref: RHSA-2002:244 | Addref: RHSA-2002:243 | Addref: RHSA-2002:222 | Change Apache Week ref to: http://www.apacheweek.com/issues/02-10-04#security | Christey> SGI:20021105-02-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20021105-02-I | View |
5233 | CVE-2002-0843 | Candidate | Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response. | Modified (20071016) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | Christey> CONFIRM:http://www.info.apple.com/usen/security/security_updates.html | Cox> Support inclusion decision: a user may well run ApacheBench against | their own server in a DMZ that has been compromised therefore leading | to a break across security zones. | Addref: RHSA-2002:251 | Addref: RHSA-2002:248 | Addref: RHSA-2002:244 | Addref: RHSA-2002:243 | Addref: RHSA-2002:222 | Change Apache Week ref to: http://www.apacheweek.com/issues/02-10-04#security | Christey> SGI:20021105-02-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20021105-02-I | Christey> BUGTRAQ:20021016 Apache 1.3.26 | URL:http://archives.neohapsis.com/archives/bugtraq/2002-10/0229.html | XF:apache-apachebench-response-bo(10281) | URL:http://www.iss.net/security_center/static/10281.php | BID:5996 | URL:http://www.securityfocus.com/bid/5996 | View |
4791 | CVE-2002-0399 | Candidate | Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267. | Modified (20100521) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2002:066 | Cox> Addref: RHSA-2002:138 | View |
6873 | CVE-2003-0044 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML. | Modified (20071121) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | REVIEWING(1) Jones | Jones> [JHJ] XSS really "execute arbitrary web script"? | CHANGE> [Cox changed vote from NOOP to MODIFY] | Cox> "Agree with Jones, wording on effect of a XSS could be better" | Christey> I"ve been trying to devise reasonable-but-short wordings for | XSS issues and the terminology just isn"t quite there yet. This | description is clearly a failed wording, however :-) | View |
4435 | CVE-2002-0041 | Candidate | Unknown vulnerability in Mail for SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, when running with the -R option, allows local and remote attackers to cause a core dump. | Modified (20050707) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:irix-mail-core-dump(8835) | View |
Page 911 of 20943, showing 5 records out of 104715 total, starting on record 4551, ending on 4555