CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1273 | CVE-1999-1293 | Candidate | mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. | Proposed (20010912) | ACCEPT(3) Armstrong, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:apache-mod-proxy-dos(7249) | CONFIRM reference no longer seems to exist. BugTraq message | seems to be a confirmation/advisory, however. | CHANGE> [Foat changed vote from ACCEPT to NOOP] | View |
8771 | CVE-2004-0343 | Candidate | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php. | Proposed (20040318) | ACCEPT(3) Armstrong, Cole, Stracener | NOOP(3) Balinsky, Cox, Wall | REVIEWING(1) Green | View | |
3316 | CVE-2001-0499 | Candidate | Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD. | Modified (20050509) | ACCEPT(3) Armstrong, Cole, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Frech> XF:oracle-tns-listener-bo(6758) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf | Christey> CERT:CA-2001-16 | URL:http://www.cert.org/advisories/CA-2001-16.html | CIAC:L-108 | URL:http://ciac.llnl.gov/ciac/bulletins/l-108.shtml | CERT-VN:VU#620495 | URL:http://www.kb.cert.org/vuls/id/620495 | BID:2941 | URL:http://www.securityfocus.com/bid/2941 | Christey> Consider adding BID:2941 | Christey> BUGTRAQ:20021126 Oracle TNS SEH Exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103833206805744&w=2 | Christey> CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf | View |
490 | CVE-1999-0492 | Candidate | The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. | Proposed (19990726) | ACCEPT(3) Armstrong, Collins, Northcutt | MODIFY(4) Baker, Blake, Frech, Shostack | NOOP(4) Christey, Cole, Landfield, Wall | REVIEWING(1) Ozancin | Shostack> isn"t that what finger is supposed to do? | Landfield> Maybe we need a new category of "unsafe system utilities and protocols" | Blake> Ffingerd 1.19 allows remote attackers to differentiate valid and invalid | usernames on the target system based on its responses to finger queries. | Christey> CHANGEREF BUGTRAQ [canonicalize] | BUGTRAQ:19990423 Ffingerd privacy issues | http://marc.theaimsgroup.com/?l=bugtraq&m=92488772121313&w=2 | | Here"s the nature of the problem. | (1) FFingerd allows users to decide not to be fingered, | printing a message "That user does not want to be fingered" | (2) If the fingered user does not exist, then FFingerd"s | intended default is to print that the user does not | want to be fingered; however, the error message has a | period at the end. | Thus, ffingerd can allow someone to determine who valid users | on the server are, *in spite of* the intended functionality of | ffingerd itself. Thus this exposure should be viewed in light | of the intended functionality of the application, as opposed | to the common usage of the finger protocol in general. | | Also, the vendor posted a followup and said that a patch was | available. See: | http://marc.theaimsgroup.com/?l=bugtraq&m=92489375428016&w=2 | Baker> Vulnerability Reference (HTML) Reference Type | http://www.securityfocus.com/archive/1/13422 Misc Defensive Info | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ffinger-user-info(5393) | View |
5785 | CVE-2002-1401 | Candidate | Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow. | Modified (20071113) | ACCEPT(3) Armstrong, Cox, Green | NOOP(2) Christey, Cole | CHANGE> [Cox changed vote from NOOP to ACCEPT] | Christey> REDHAT:RHSA-2003:010 | View |
Page 919 of 20943, showing 5 records out of 104715 total, starting on record 4591, ending on 4595