CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4423 | CVE-2002-0029 | Candidate | Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684. | Modified (20060523) | ACCEPT(3) Baker, Cole, Frech | MODIFY(1) Cox | NOOP(2) Christey, Wall | CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> ADDREF: REDHAT: http://rhn.redhat.com/cve/CVE-2002-0029.html | Christey> the redhat reference is REDHAT:RHSA-2004:383 | View |
737 | CVE-1999-0757 | Candidate | The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates. | Proposed (20010214) | ACCEPT(3) Baker, Cole, Frech | NOOP(1) Christey | Frech> XF:coldfusion-encryption | Christey> BUGTRAQ:19990724 Re: New Allaire Security Zone Bulletins and KB Articles | URL:http://www.securityfocus.com/archive/1/19471 | Christey> ADDREF BID:275 | URL:http://www.securityfocus.com/bid/275 | View |
5350 | CVE-2002-0962 | Candidate | Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event, (2) the topic parameter in index.php, or (3) the title parameter in comment.php. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Frech | NOOP(2) Foat, Wall | View | |
5351 | CVE-2002-0963 | Candidate | SQL injection vulnerability in comment.php for GeekLog 1.3.5 and earlier allows remote attackers to obtain sensitive user information via the pid parameter. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Frech | NOOP(2) Foat, Wall | View | |
5056 | CVE-2002-0666 | Candidate | IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors. | Modified (20050601) | ACCEPT(3) Baker, Cole, Frech | NOOP(3) Christey, Cox, Wall | Christey> DEBIAN:DSA-201 | View |
Page 925 of 20943, showing 5 records out of 104715 total, starting on record 4621, ending on 4625