CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4984  CVE-2002-0593  Candidate  Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.  Modified (20071113)  ACCEPT(3) Baker, Cole, Cox | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:mozilla-netscape-irc-bo(8976) | CHANGE> [Cox changed vote from REVIEWING to ACCEPT]  View
5477  CVE-2002-1090  Candidate  Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Cox | NOOP(2) Christey, Wall  Christey> REDHAT:RHSA-2003:109 | URL:http://www.redhat.com/support/errata/RHSA-2003-109.html | Christey> CONECTIVA:CLA-2003:630 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000630  View
2723  CVE-2000-1156  Candidate  StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.  Modified (20010116-01)  ACCEPT(3) Baker, Cole, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:staroffice-tmp-sym-link(5487) | Christey> Consult Sun on this one. | Dik> Supposedly fixed in Soffice 5.1 Service pack 1  View
2458  CVE-2000-0889  Candidate  Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.  Proposed (20010202)  ACCEPT(3) Baker, Cole, Dik | MODIFY(1) Frech | NOOP(2) Wall, Ziese | REVIEWING(1) Christey  Frech> XF:sun-compromised-certificate(5404) | Christey> Should revoked cert"s be included in CVE? How about the ones | for Microsoft from early 2001?  View
5275  CVE-2002-0885  Candidate  Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Frech | MODIFY(1) Alderson | NOOP(5) Armstrong, Christey, Cox, Foat, Jones  Jones> Need clarification/verification. | Alderson> Personally, since this one is not only vague, but extremely vague | and not even confirmed, I believe it should be lumped with the previous one | that has been confirmed and is much less vague. | Christey> Correction: this is a RARP (Reverse Address Resolution | Protocol) server. | A colleague of mine with access to Solaris source has noted | that the affected syslog calls can not be fed user-supplied | data, at least for Solaris; if so, then this is not a vulnerability.  View

Page 924 of 20943, showing 5 records out of 104715 total, starting on record 4616, ending on 4620

Actions