CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1273  CVE-1999-1293  Candidate  mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.  Proposed (20010912)  ACCEPT(3) Armstrong, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:apache-mod-proxy-dos(7249) | CONFIRM reference no longer seems to exist. BugTraq message | seems to be a confirmation/advisory, however. | CHANGE> [Foat changed vote from ACCEPT to NOOP]  View
8771  CVE-2004-0343  Candidate  Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.  Proposed (20040318)  ACCEPT(3) Armstrong, Cole, Stracener | NOOP(3) Balinsky, Cox, Wall | REVIEWING(1) Green    View
3316  CVE-2001-0499  Candidate  Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.  Modified (20050509)  ACCEPT(3) Armstrong, Cole, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:oracle-tns-listener-bo(6758) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf | Christey> CERT:CA-2001-16 | URL:http://www.cert.org/advisories/CA-2001-16.html | CIAC:L-108 | URL:http://ciac.llnl.gov/ciac/bulletins/l-108.shtml | CERT-VN:VU#620495 | URL:http://www.kb.cert.org/vuls/id/620495 | BID:2941 | URL:http://www.securityfocus.com/bid/2941 | Christey> Consider adding BID:2941 | Christey> BUGTRAQ:20021126 Oracle TNS SEH Exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103833206805744&w=2 | Christey> CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf  View
490  CVE-1999-0492  Candidate  The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.  Proposed (19990726)  ACCEPT(3) Armstrong, Collins, Northcutt | MODIFY(4) Baker, Blake, Frech, Shostack | NOOP(4) Christey, Cole, Landfield, Wall | REVIEWING(1) Ozancin  Shostack> isn"t that what finger is supposed to do? | Landfield> Maybe we need a new category of "unsafe system utilities and protocols" | Blake> Ffingerd 1.19 allows remote attackers to differentiate valid and invalid | usernames on the target system based on its responses to finger queries. | Christey> CHANGEREF BUGTRAQ [canonicalize] | BUGTRAQ:19990423 Ffingerd privacy issues | http://marc.theaimsgroup.com/?l=bugtraq&m=92488772121313&w=2 | | Here"s the nature of the problem. | (1) FFingerd allows users to decide not to be fingered, | printing a message "That user does not want to be fingered" | (2) If the fingered user does not exist, then FFingerd"s | intended default is to print that the user does not | want to be fingered; however, the error message has a | period at the end. | Thus, ffingerd can allow someone to determine who valid users | on the server are, *in spite of* the intended functionality of | ffingerd itself. Thus this exposure should be viewed in light | of the intended functionality of the application, as opposed | to the common usage of the finger protocol in general. | | Also, the vendor posted a followup and said that a patch was | available. See: | http://marc.theaimsgroup.com/?l=bugtraq&m=92489375428016&w=2 | Baker> Vulnerability Reference (HTML) Reference Type | http://www.securityfocus.com/archive/1/13422 Misc Defensive Info | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ffinger-user-info(5393)  View
5785  CVE-2002-1401  Candidate  Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.  Modified (20071113)  ACCEPT(3) Armstrong, Cox, Green | NOOP(2) Christey, Cole  CHANGE> [Cox changed vote from NOOP to ACCEPT] | Christey> REDHAT:RHSA-2003:010  View

Page 919 of 20943, showing 5 records out of 104715 total, starting on record 4591, ending on 4595

Actions