|
Name: CVE-2004-0002
Description:
The TCP MSS (maximum segment size) functionality in
netinet allows remote attackers to cause a denial of
service (resource exhaustion) via (1) a low MTU, which
causes a large number of small packets to be produced,
or (2) via a large number of packets with a small TCP
payload, which cause a large number of calls to the
resource-intensive sowakeup function.
Status: Candidate
Phase: Proposed (20040318)
Reference:
CONFIRM:http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html
Votes:
ACCEPT(4) Williams, Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0003
Description:
Unknown vulnerability in Linux kernel before 2.4.22
allows local users to gain privileges, related to "R128
DRI limits checking."
Status: Candidate
Phase: Modified (20061101)
Reference:
CONFIRM:http://www.linuxcompatible.org/print25630.html
Reference: DEBIAN:DSA-479
Reference:
URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference:
URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference:
URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference:
URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference:
URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference:
URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference:
URL:http://www.debian.org/security/2004/dsa-495
Reference: MANDRAKE:MDKSA-2004:029
Reference:
URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:044
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-044.html
Reference: REDHAT:RHSA-2004:065
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-065.html
Reference: REDHAT:RHSA-2004:106
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-106.html
Reference: REDHAT:RHSA-2004:166
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-166.html
Reference: SUSE:SuSE-SA:2004:005
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html
Reference: TURBO:TLSA-2004-14
Reference:
URL:http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
Reference: CIAC:O-082
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-082.shtml
Reference: CIAC:O-121
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-126
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-126.shtml
Reference: CIAC:O-127
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: CIAC:O-145
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-145.shtml
Reference: BID:9570
Reference:
URL:http://www.securityfocus.com/bid/9570
Reference: SECUNIA:10782
Reference:
URL:http://secunia.com/advisories/10782
Reference: SECUNIA:10911
Reference:
URL:http://secunia.com/advisories/10911
Reference: SECUNIA:10912
Reference:
URL:http://secunia.com/advisories/10912
Reference: SECUNIA:11202
Reference:
URL:http://secunia.com/advisories/11202
Reference: SECUNIA:11361
Reference:
URL:http://secunia.com/advisories/11361
Reference: SECUNIA:11362
Reference:
URL:http://secunia.com/advisories/11362
Reference: SECUNIA:11369
Reference:
URL:http://secunia.com/advisories/11369
Reference: SECUNIA:11370
Reference:
URL:http://secunia.com/advisories/11370
Reference: SECUNIA:11376
Reference:
URL:http://secunia.com/advisories/11376
Reference: SECUNIA:11464
Reference:
URL:http://secunia.com/advisories/11464
Reference: SECUNIA:11891
Reference:
URL:http://secunia.com/advisories/11891
Reference: SECUNIA:12075
Reference:
URL:http://secunia.com/advisories/12075
Reference: OVAL:oval:org.mitre.oval:def:1017
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017
Reference: OVAL:oval:org.mitre.oval:def:834
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834
Reference: XF:linux-r128-gain-priviliges(15029)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15029
Votes:
ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
NOOP(2) Christey, Wall
Voter Comments:
Christey> DEBIAN:DSA-479
URL:http://www.debian.org/security/2004/dsa-479
DEBIAN:DSA-480
URL:http://www.debian.org/security/2004/dsa-480
DEBIAN:DSA-481
URL:http://www.debian.org/security/2004/dsa-481
DEBIAN:DSA-482
URL:http://www.debian.org/security/2004/dsa-482
Christey> DEBIAN:DSA-489
URL:http://www.debian.org/security/2004/dsa-489
DEBIAN:DSA-491
URL:http://www.debian.org/security/2004/dsa-491
Christey> DEBIAN:DSA-495
URL:http://www.debian.org/security/2004/dsa-495
REDHAT:RHSA-2004:166
URL:http://rhn.redhat.com/errata/RHSA-2004-166.html
Christey> REDHAT:RHSA-2004:188
URL:http://www.redhat.com/support/errata/RHSA-2004-188.html
Christey> CONECTIVA:CLA-2004:846
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Name: CVE-2004-0005
Description:
Multiple buffer overflows in Gaim 0.75 allow remote
attackers to cause a denial of service and possibly
execute arbitrary code via (1) octal encoding in
yahoo_decode that causes a null byte to be written
beyond the buffer, (2) octal encoding in yahoo_decode
that causes a pointer to reference memory beyond the
terminating null byte, (3) a quoted printable string to
the gaim_quotedp_decode MIME decoder that causes a null
byte to be written beyond the buffer, and (4) quoted
printable encoding in gaim_quotedp_decode that causes a
pointer to reference memory beyond the terminating null
byte.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference:
MISC:http://security.e-matters.de/advisories/012004.html
Reference: CONECTIVA:CLA-2004:813
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: DEBIAN:DSA-434
Reference:
URL:http://www.debian.org/security/2004/dsa-434
Reference: GENTOO:GLSA-200401-04
Reference:
URL:http://www.linuxsecurity.com/content/view/105690/104/
Reference: SLACKWARE:SSA:2004-026
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
Reference: SUSE:SuSE-SA:2004:004
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_04_gaim.html
Reference: CERT-VN:VU#190366
Reference:
URL:http://www.kb.cert.org/vuls/id/190366
Reference: CERT-VN:VU#226974
Reference:
URL:http://www.kb.cert.org/vuls/id/226974
Reference: CERT-VN:VU#404470
Reference:
URL:http://www.kb.cert.org/vuls/id/404470
Reference: CERT-VN:VU#655974
Reference:
URL:http://www.kb.cert.org/vuls/id/655974
Reference: OSVDB:3736
Reference: URL:http://www.osvdb.org/3736
Reference: SECTRACK:1008850
Reference:
URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-mime-decoder-bo(14942)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14942
Reference: XF:gaim-mime-decoder-oob(14944)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14944
Reference: XF:gaim-yahoodecode-offbyone-bo(14935)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14935
Reference: XF:gaim-sscanf-oob(14938)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14938
Votes:
ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
NOOP(2) Christey, Wall
Voter Comments:
Christey> CERT-VN:VU#404470
URL:http://www.kb.cert.org/vuls/id/404470
CERT-VN:VU#655974
URL:http://www.kb.cert.org/vuls/id/655974
CERT-VN:VU#226974
URL:http://www.kb.cert.org/vuls/id/226974
CERT-VN:VU#190366
URL:http://www.kb.cert.org/vuls/id/190366
Name: CVE-2004-0006
Description:
Multiple buffer overflows in Gaim 0.75 and earlier, and
Ultramagnetic before 0.81, allow remote attackers to
cause a denial of service and possibly execute arbitrary
code via (1) cookies in a Yahoo web connection, (2) a
long name parameter in the Yahoo login web page, (3) a
long value parameter in the Yahoo login page, (4) a YMSG
packet, (5) the URL parser, and (6) HTTP proxy connect.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference:
MISC:http://security.e-matters.de/advisories/012004.html
Reference: BUGTRAQ:20040127 Ultramagnetic
Advisory #001: Multiple vulnerabilities in Gaim code
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522432613022&w=2
Reference:
CONFIRM:http://ultramagnetic.sourceforge.net/advisories/001.html
Reference: REDHAT:RHSA-2004:032
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-032.html
Reference: REDHAT:RHSA-2004:033
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-033.html
Reference: REDHAT:RHSA-2004:045
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-045.html
Reference: MANDRAKE:MDKSA-2004:006
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:006
Reference: SGI:20040202-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: SUSE:SuSE-SA:2004:004
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_04_gaim.html
Reference: DEBIAN:DSA-434
Reference:
URL:http://www.debian.org/security/2004/dsa-434
Reference: CONECTIVA:CLA-2004:813
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: SGI:20040201-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
Reference: SLACKWARE:SSA:2004-026
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
Reference: GENTOO:GLSA-200401-04
Reference:
URL:http://security.gentoo.org/glsa/glsa-200401-04.xml
Reference: CERT-VN:VU#297198
Reference:
URL:http://www.kb.cert.org/vuls/id/297198
Reference: CERT-VN:VU#371382
Reference:
URL:http://www.kb.cert.org/vuls/id/371382
Reference: CERT-VN:VU#444158
Reference:
URL:http://www.kb.cert.org/vuls/id/444158
Reference: CERT-VN:VU#503030
Reference:
URL:http://www.kb.cert.org/vuls/id/503030
Reference: CERT-VN:VU#527142
Reference:
URL:http://www.kb.cert.org/vuls/id/527142
Reference: CERT-VN:VU#871838
Reference:
URL:http://www.kb.cert.org/vuls/id/871838
Reference: BID:9489
Reference:
URL:http://www.securityfocus.com/bid/9489
Reference: OSVDB:3731
Reference: URL:http://www.osvdb.org/3731
Reference: OSVDB:3732
Reference: URL:http://www.osvdb.org/3732
Reference: OVAL:oval:org.mitre.oval:def:818
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818
Reference: SECTRACK:1008850
Reference:
URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-http-proxy-bo(14947)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14947
Reference: XF:gaim-login-name-bo(14940)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14940
Reference: XF:gaim-login-value-bo(14941)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14941
Reference: XF:gaim-urlparser-bo(14945)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14945
Reference:
XF:gaim-yahoopacketread-keyname-bo(14943)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14943
Reference:
XF:gaim-yahoowebpending-cookie-bo(14939)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14939
Votes:
ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
NOOP(2) Christey, Wall
Voter Comments:
Cox> Although the 0.59.1 version of Gaim shipped by Red Hat contained these
flaws, Yahoo connections were not functional and therefore the majority of
the issues could not be exploited, leading to the abstraction comment above.
Christey> CERT-VN:VU#871838
URL:http://www.kb.cert.org/vuls/id/871838
CERT-VN:VU#444158
URL:http://www.kb.cert.org/vuls/id/444158
CERT-VN:VU#503030
URL:http://www.kb.cert.org/vuls/id/503030
CERT-VN:VU#371382
URL:http://www.kb.cert.org/vuls/id/371382
CERT-VN:VU#297198
URL:http://www.kb.cert.org/vuls/id/297198
CERT-VN:VU#527142
URL:http://www.kb.cert.org/vuls/id/527142
Christey> Normalize Gentoo reference
Name: CVE-2004-0007
Description:
Buffer overflow in the Extract Info Field Function for
(1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and
earlier, and Ultramagnetic before 0.81, allows remote
attackers to cause a denial of service and possibly
execute arbitrary code.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference:
MISC:http://security.e-matters.de/advisories/012004.html
Reference: BUGTRAQ:20040127 Ultramagnetic
Advisory #001: Multiple vulnerabilities in Gaim code
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522432613022&w=2
Reference:
CONFIRM:http://ultramagnetic.sourceforge.net/advisories/001.html
Reference: CONECTIVA:CLA-2004:813
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: DEBIAN:DSA-434
Reference:
URL:http://www.debian.org/security/2004/dsa-434
Reference: GENTOO:GLSA-200401-04
Reference:
URL:http://security.gentoo.org/glsa/glsa-200401-04.xml
Reference: MANDRAKE:MDKSA-2004:006
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:006
Reference: REDHAT:RHSA-2004:032
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-032.html
Reference: REDHAT:RHSA-2004:033
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-033.html
Reference: SLACKWARE:SSA:2004-026
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
Reference: SUSE:SuSE-SA:2004:004
Reference:
URL:http://www.securityfocus.com/advisories/6281
Reference: CERT-VN:VU#197142
Reference:
URL:http://www.kb.cert.org/vuls/id/197142
Reference: BID:9489
Reference:
URL:http://www.securityfocus.com/bid/9489
Reference: OSVDB:3733
Reference: URL:http://www.osvdb.org/3733
Reference: OVAL:oval:org.mitre.oval:def:819
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819
Reference: SECTRACK:1008850
Reference:
URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-extractinfo-bo(14946)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14946
Votes:
ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
NOOP(2) Christey, Wall
Voter Comments:
Christey> Normalize Gentoo, Slackware reference
Christey> CERT-VN:VU#197142
Name: CVE-2004-0008
Description:
Integer overflow in Gaim 0.74 and earlier, and
Ultramagnetic before 0.81, allows remote attackers to
cause a denial of service and possibly execute arbitrary
code via a directIM packet that triggers a heap-based
buffer overflow.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12
x Gaim remote overflows
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference:
MISC:http://security.e-matters.de/advisories/012004.html
Reference: BUGTRAQ:20040127 Ultramagnetic
Advisory #001: Multiple vulnerabilities in Gaim code
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522432613022&w=2
Reference:
CONFIRM:http://ultramagnetic.sourceforge.net/advisories/001.html
Reference: REDHAT:RHSA-2004:032
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-032.html
Reference: REDHAT:RHSA-2004:033
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-033.html
Reference: MANDRAKE:MDKSA-2004:006
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:006
Reference: DEBIAN:DSA-434
Reference:
URL:http://www.debian.org/security/2004/dsa-434
Reference: REDHAT:RHSA-2004:045
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-045.html
Reference: CONECTIVA:CLA-2004:813
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: SGI:20040201-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
Reference: BUGTRAQ:20040127 [slackware-security]
GAIM security update (SSA:2004-026-01)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522338611564&w=2
Reference: GENTOO:GLSA-200401-04
Reference:
URL:http://security.gentoo.org/glsa/glsa-200401-04.xml
Reference: SGI:20040202-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: CERT-VN:VU#779614
Reference:
URL:http://www.kb.cert.org/vuls/id/779614
Reference: OSVDB:3734
Reference: URL:http://www.osvdb.org/3734
Reference: OVAL:oval:org.mitre.oval:def:820
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820
Reference: SECTRACK:1008850
Reference:
URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-directim-bo(14937)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14937
Votes:
ACCEPT(6) Green, Wall, Baker, Cole, Armstrong, Cox
NOOP(1) Christey
Voter Comments:
Christey> CERT-VN:VU#779614
Name: CVE-2004-0010
Description:
Stack-based buffer overflow in the ncp_lookup function
for ncpfs in Linux kernel 2.4.x allows local users to
gain privileges.
Status: Candidate
Phase: Assigned (20040105)
Reference: CONECTIVA:CLA-2004:820
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000820
Reference: DEBIAN:DSA-479
Reference:
URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference:
URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference:
URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference:
URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference:
URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference:
URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference:
URL:http://www.debian.org/security/2004/dsa-495
Reference: FEDORA:FEDORA-2004-079
Reference:
URL:http://fedoranews.org/updates/FEDORA-2004-079.shtml
Reference: MANDRAKE:MDKSA-2004:015
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:015
Reference: REDHAT:RHSA-2004:065
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-065.html
Reference: REDHAT:RHSA-2004:069
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-069.html
Reference: REDHAT:RHSA-2004:188
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-188.html
Reference: SUSE:SuSE-SA:2004:005
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html
Reference: TURBO:TLSA-2004-05
Reference:
URL:http://www.securityfocus.com/advisories/6759
Reference: CIAC:O-082
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-082.shtml
Reference: BID:9691
Reference:
URL:http://www.securityfocus.com/bid/9691
Reference:
XF:linux-ncplookup-gain-privileges(15250)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15250
Reference: OVAL:oval:org.mitre.oval:def:1035
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035
Reference: OVAL:oval:org.mitre.oval:def:835
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835
Votes:
Name: CVE-2004-0012
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040105)
Votes:
Name: CVE-2004-0014
Description:
Multiple buffer overflows in the nd WebDAV interface
0.8.2 and earlier allows remote web servers to execute
arbitrary code via certain long strings.
Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-412
Reference:
URL:http://www.debian.org/security/2004/dsa-412
Reference: BID:9365
Reference:
URL:http://www.securityfocus.com/bid/9365
Reference: SECTRACK:1008616
Reference:
URL:http://www.securitytracker.com/id?1008616
Reference: SECUNIA:10549
Reference:
URL:http://secunia.com/advisories/10549
Reference: SECUNIA:10550
Reference:
URL:http://secunia.com/advisories/10550
Reference: XF:nd-long-string-bo(14141)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14141
Votes:
ACCEPT(3) Baker, Cole, Armstrong
MODIFY(1) Williams
NOOP(2) Wall, Cox
Voter Comments:
Williams> need to change desc. i think this was fixed in 0.8.2.
http://www.gohome.org/nd
Name: CVE-2004-0017
Description:
Multiple SQL injection vulnerabilities in the (1)
calendar and (2) infolog modules for phpgroupware 0.9.14
allow remote attackers to perform unauthorized database
operations.
Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-419
Reference:
URL:http://www.debian.org/security/2004/dsa-419
Reference: BID:9386
Reference:
URL:http://www.securityfocus.com/bid/9386
Reference: SECTRACK:1008662
Reference:
URL:http://www.securitytracker.com/id?1008662
Reference: SECUNIA:10591
Reference:
URL:http://secunia.com/advisories/10591
Votes:
ACCEPT(3) Baker, Cole, Armstrong
MODIFY(1) Williams
NOOP(2) Wall, Cox
Voter Comments:
Williams> i believe this affects phpGroupWare 0.9.14.006 and earlier, and phpGroupWare 0.9.16RC1 and earlier.
http://phpgroupware.org/downloads
Name: CVE-2004-0018
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0019
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0020
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0021
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0022
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0023
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0024
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0025
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0026
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0027
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040106)
Votes:
Name: CVE-2004-0029
Description:
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini
configuration file with world-writable permissions,
which allows local users to modify the Notes
configuration and gain privileges.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040106 Lotus Notes Domino
6.0.2 (linux) faulty default permissions
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340897710308&w=2
Reference:
MISC:http://www.excluded.org/advisories/advisory05.txt
Reference: BID:9366
Reference:
URL:http://www.securityfocus.com/bid/9366
Reference: OSVDB:3424
Reference: URL:http://www.osvdb.org/3424
Reference: SECTRACK:1008623
Reference:
URL:http://www.securitytracker.com/id?1008623
Reference: SECUNIA:10566
Reference:
URL:http://secunia.com/advisories/10566
Reference:
XF:lotus-notes-insecure-permissions(14153)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14153
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
Williams> insufficient data.
Name: CVE-2004-0030
Description:
PHP remote file inclusion vulnerability in (1)
functions.php, (2) authentication_index.php, and (3)
config_gedcom.php for PHPGEDVIEW 2.61 allows remote
attackers to execute arbitrary PHP code by modifying the
PGV_BASE_DIRECTORY parameter to reference a URL on a
remote web server that contains the code.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040106 Vuln in PHPGEDVIEW
2.61 Multi-Problem
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340840209453&w=2
Reference: BID:9368
Reference:
URL:http://www.securityfocus.com/bid/9368
Reference: OSVDB:3343
Reference: URL:http://www.osvdb.org/3343
Reference: SECTRACK:1008632
Reference:
URL:http://www.securitytracker.com/id?1008632
Reference: SECUNIA:10565
Reference:
URL:http://secunia.com/advisories/10565
Reference:
XF:phpgedview-pgvbasedirectory-file-include(14159)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14159
Votes:
ACCEPT(3) Williams, Baker, Armstrong
NOOP(3) Wall, Cole, Cox
Voter Comments:
Williams> http://phpgedview.sourceforge.net/
Name: CVE-2004-0034
Description:
Multiple cross-site scripting (XSS) vulnerabilities in
Phorum 3.4.5 and earlier allow remote attackers to
inject arbitrary HTML or web script via (1) the
phorum_check_xss function in common.php, (2) the
EditError variable in profile.php, and (3) the Error
variable in login.php.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040105 Multiple
Vulnerabilities in Phorum 3.4.5
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340481804110&w=2
Reference: CONFIRM:http://phorum.org/
Reference: BID:9361
Reference:
URL:http://www.securityfocus.com/bid/9361
Reference: OSVDB:3434
Reference: URL:http://www.osvdb.org/3434
Reference: OSVDB:3506
Reference: URL:http://www.osvdb.org/3506
Reference: OSVDB:3510
Reference: URL:http://www.osvdb.org/3510
Reference: SECTRACK:1008633
Reference:
URL:http://www.securitytracker.com/id?1008633
Reference: SECUNIA:10567
Reference:
URL:http://secunia.com/advisories/10567
Reference: XF:phorum-common-xss(14145)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14145
Votes:
ACCEPT(4) Williams, Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0037
Description:
FirstClass Desktop Client 7.1 allows remote attackers to
execute arbitrary commands via hyperlinks in FirstClass
RTF messages.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040105 FirstClass Client
7.1: Command Execution via Email Web Link
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340950611167&w=2
Reference: BID:9370
Reference:
URL:http://www.securityfocus.com/bid/9370
Reference: OSVDB:3442
Reference: URL:http://www.osvdb.org/3442
Reference: SECTRACK:1008609
Reference:
URL:http://www.securitytracker.com/id?1008609
Reference: SECUNIA:10556
Reference:
URL:http://secunia.com/advisories/10556
Reference:
XF:firstclassclient-execute-code(14151)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14151
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
Williams> insufficient data.
Name: CVE-2004-0038
Description:
McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0
SP2a Patch 3 allows remote attackers to execute
arbitrary commands via certain HTTP POST requests to the
spipe/file handler on ePO TCP port 81.
Status: Candidate
Phase: Assigned (20040107)
Reference: ISS:20040510 McAfee ePolicy
Orchestrator Remote Compromise Vulnerability
Reference:
URL:http://xforce.iss.net/xforce/alerts/id/173
Reference:
CONFIRM:http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt
Reference: MISC:http://www.osvdb.org/5626
Reference: XF:epolicy-execute-commands(14166)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14166
Reference: BID:10200
Reference:
URL:http://www.securityfocus.com/bid/10200
Votes:
Name: CVE-2004-0039
Description:
Multiple format string vulnerabilities in HTTP
Application Intelligence (AI) component in Check Point
Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1
HTTP Security Server included with NG FP1, FP2, and FP3
allows remote attackers to execute arbitrary code via
HTTP requests that cause format string specifiers to be
used in an error message, as demonstrated using the
scheme of a URI.
Status: Candidate
Phase: Modified (20050818)
Reference: ISS:20040204 Checkpoint Firewall-1
HTTP Parsing Format String Vulnerabilities
Reference:
URL:http://xforce.iss.net/xforce/alerts/id/162
Reference: BUGTRAQ:20040205 Two checkpoint
fw-1/vpn-1 vulns
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107604682227031&w=2
Reference:
CONFIRM:http://www.checkpoint.com/techsupport/alerts/security_server.html
Reference: CERT:TA04-036A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-036A.html
Reference: CERT-VN:VU#790771
Reference:
URL:http://www.kb.cert.org/vuls/id/790771
Reference: CIAC:O-072
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-072.shtml
Reference: XF:fw1-format-string(14149)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14149
Reference: BID:9581
Reference:
URL:http://www.securityfocus.com/bid/9581
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
NOOP(1) Cox
Name: CVE-2004-0041
Description:
The mod_auth_shadow module 1.4 and earlier does not
properly enforce the expiration of a user account and
password, which could allow remote authenticated users
to bypass intended access restrictions.
Status: Candidate
Phase: Assigned (20040107)
Reference: DEBIAN:DSA-421
Reference:
URL:http://www.debian.org/security/2004/dsa-421
Reference: BID:9404
Reference:
URL:http://www.securityfocus.com/bid/9404
Reference: OSVDB:3454
Reference: URL:http://www.osvdb.org/3454
Reference: SECTRACK:1008675
Reference:
URL:http://www.securitytracker.com/id?1008675
Reference: SECUNIA:10612
Reference:
URL:http://secunia.com/advisories/10612
Votes:
Name: CVE-2004-0042
Description:
vsftpd 1.1.3 generates different error messages
depending on whether or not a valid username exists,
which allows remote attackers to identify valid
usernames.
Status: Candidate
Phase: Modified (20050526)
Reference: SECTRACK:1008628
Reference:
URL:http://securitytracker.com/id?1008628
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(3) Williams, Wall, Cole
REJECT(1) Cox
Voter Comments:
Williams> insufficient data.
CHANGE> [Cox changed vote from REVIEWING to REJECT]
Cox> Expected behaviour. By source code analysis the difference in
behaviour mentioned in the report only occurs when an administrator has
configured the server with an explicit userlist - either to allow or deny
all users in the userlist. The vsftpd manual page states that if a
userlist is used then the user will be denied access before they are asked
for a password to help prevent cleartext passwords being transmitted.
Administrators who don't want this behaviour do not need to configure an
optional userlist.
Name: CVE-2004-0043
Description:
Buffer overflow in Yahoo Instant Messenger 5.6.0.1351
and earlier allows remote attackers to cause a denial of
service (crash) and possibly execute arbitrary code via
a long filename in the download feature.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040108 Yahoo Instant
Messenger Long Filename Downloading Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107357996802255&w=2
Reference: FULLDISC:20040108 Yahoo Instant
Messenger Long Filename Downloading Buffer Overflow
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html
Reference: BID:9383
Reference:
URL:http://www.securityfocus.com/bid/9383
Reference: OSVDB:3437
Reference: URL:http://www.osvdb.org/3437
Reference: SECTRACK:1008651
Reference:
URL:http://www.securitytracker.com/id?1008651
Reference: SECUNIA:10573
Reference:
URL:http://secunia.com/advisories/10573
Reference: XF:yahoo-messenger-filename-bo(14171)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14171
Votes:
ACCEPT(3) Williams, Baker, Armstrong
NOOP(2) Cole, Cox
REVIEWING(1) Wall
Voter Comments:
Williams> http://lists.netsys.com/pipermail/full-disclosure/2004-January/015355.html
http://www.packetstormsecurity.nl/0401-advisories/yahooIM.txt
Name: CVE-2004-0046
Description:
Cross-site scripting (XSS) vulnerability in SnapStream
PVS LITE allows remote attackers to inject arbitrary web
script or HTML via a GET request containing a
terminating '"' (double quote) character.
Status: Candidate
Phase: Modified (20050430)
Reference: BUGTRAQ:20040106 SnapStream PVS LITE
Cross Site Scripting Vulnerabillity
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107350313917867&w=2
Reference: BID:9375
Reference:
URL:http://www.securityfocus.com/bid/9375
Reference: OSVDB:3440
Reference: URL:http://www.osvdb.org/3440
Reference: SECTRACK:1008646
Reference:
URL:http://securitytracker.com/id?1008646
Reference: SECUNIA:10575
Reference:
URL:http://secunia.com/advisories/10575
Reference: XF:snapstream-quotation-xss(14164)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14164
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
Williams> insufficient data.
Name: CVE-2004-0047
Description:
Multiple programs in trr19 1.0 do not properly drop
privileges before executing a system command, which
could allow local users to gain privileges.
Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-430
Reference:
URL:http://www.debian.org/security/2004/dsa-430
Reference: BID:9520
Reference:
URL:http://www.securityfocus.com/bid/9520
Reference: OSVDB:3747
Reference: URL:http://www.osvdb.org/3747
Reference: SECTRACK:1008875
Reference:
URL:http://www.securitytracker.com/id?1008875
Reference: SECUNIA:10744
Reference:
URL:http://secunia.com/advisories/10744/
Reference: SECUNIA:10745
Reference:
URL:http://secunia.com/advisories/10745
Reference: XF:trr19-gain-privileges(14975)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14975
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0048
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040113)
Votes:
Name: CVE-2004-0050
Description:
Verity Ultraseek before 5.2.2 allows remote attackers to
obtain the full pathname of the document root via an
MS-DOS device name in the web search option, such as (1)
NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.
Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040505 Corsaire Security
Advisory - Verity Ultraseek path disclosure issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108377388114888&w=2
Reference: VULNWATCH:20040505 Corsaire Security
Advisory - Verity Ultraseek path disclosure issue
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0024.html
Reference: FULLDISC:20040505 Corsaire Security
Advisory - Verity Ultraseek path disclosure issue
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020952.html
Reference:
XF:ultraseek-error-path-disclosure(16066)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16066
Votes:
Name: CVE-2004-0051
Description:
Multiple content security gateway and antivirus products
allow remote attackers to bypass content restrictions
via MIME messages that use non-standard but frequently
supported Content-Transfer-Encoding values such as (1)
uuencode, (2) mac-binhex40, and (3) yenc, which may be
interpreted differently by mail clients.
Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040914 Corsaire Security
Advisory - Multiple vendor MIME
Content-Transfer-Encoding mechanism issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109517788100063&w=2
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference:
XF:mime-contenttransfer-filter-bypass(17337)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17337
Votes:
Name: CVE-2004-0052
Description:
Multiple content security gateway and antivirus products
allow remote attackers to bypass content restrictions
via MIME messages that use non-standard separator
characters, or use standard separators incorrectly,
within MIME headers, fields, parameters, or values,
which may be interpreted differently by mail clients.
Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040914 Corsaire Security
Advisory - Multiple vendor MIME separator issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109517669115891&w=2
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference:
XF:mime-separator-filtering-bypass(17334)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17334
Votes:
Name: CVE-2004-0053
Description:
Multiple content security gateway and antivirus products
allow remote attackers to bypass content restrictions
via MIME messages that use fields that use RFC2047
encoding, which may be interpreted differently by mail
clients.
Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040914 Corsaire Security
Advisory - Multiple vendor MIME RFC2047 encoding issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109520704408739&w=2
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference:
XF:mime-rfc2047-filtering-bypass(17331)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17331
Votes:
Name: CVE-2004-0054
Description:
Multiple vulnerabilities in the H.323 protocol
implementation for Cisco IOS 11.3T through 12.2T allow
remote attackers to cause a denial of service and
possibly execute arbitrary code, as demonstrated by the
NISCC/OUSPG PROTOS test suite for the H.225 protocol.
Status: Candidate
Phase: Modified (20071113)
Reference: CISCO:20040113 Vulnerabilities in
H.323 Message Processing
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
Reference: CERT:CA-2004-01
Reference:
URL:http://www.cert.org/advisories/CA-2004-01.html
Reference: CERT-VN:VU#749342
Reference:
URL:http://www.kb.cert.org/vuls/id/749342
Reference: BID:9406
Reference:
URL:http://www.securityfocus.com/bid/9406
Reference: SECTRACK:1008685
Reference:
URL:http://www.securitytracker.com/id?1008685
Votes:
ACCEPT(5) Green, Wall, Baker, Cole, Armstrong
NOOP(1) Cox
Name: CVE-2004-0055
Description:
The print_attr_string function in print-radius.c for
tcpdump 3.8.1 and earlier allows remote attackers to
cause a denial of service (segmentation fault) via a
RADIUS attribute with a large length value.
Status: Candidate
Phase: Modified (20071129)
Reference: MLIST:[tcpdump-workers] multiple
vulnerabilities in tcpdump 3.8.1
Reference:
URL:http://marc.theaimsgroup.com/?l=tcpdump-workers&m=107325073018070&w=2
Reference: APPLE:APPLE-SA-2004-02-23
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: CONECTIVA:CLSA-2003:832
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000832
Reference: FEDORA:FLSA:1222
Reference:
URL:http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html
Reference: REDHAT:RHSA-2004:008
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-008.html
Reference: DEBIAN:DSA-425
Reference:
URL:http://www.debian.org/security/2004/dsa-425
Reference: MANDRAKE:MDKSA-2004:008
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:008
Reference: SGI:20040103-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
Reference: BUGTRAQ:20040131 [FLSA-2004:1222]
Updated tcpdump resolves security vulnerabilites (resend
with correct paths)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577418225627&w=2
Reference: SGI:20040202-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: CERT-VN:VU#955526
Reference:
URL:http://www.kb.cert.org/vuls/id/955526
Reference: BID:7090
Reference:
URL:http://www.securityfocus.com/bid/7090
Reference: OVAL:oval:org.mitre.oval:def:850
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850
Reference: OVAL:oval:org.mitre.oval:def:853
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853
Reference: SECTRACK:1008735
Reference:
URL:http://www.securitytracker.com/id?1008735
Votes:
ACCEPT(6) Williams, Wall, Baker, Cole, Armstrong, Cox
NOOP(1) Christey
Voter Comments:
Cox> ADDREF: REDHAT:RHSA-2004:007
Williams> http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-isakmp.c
Christey> SCO:SCOSA-2004.9
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt
Name: CVE-2004-0056
Description:
Multiple vulnerabilities in the H.323 protocol
implementation for Nortel Networks Business
Communications Manager (BCM), Succession 1000 IP Trunk
and IP Peer Networking, and 802.11 Wireless IP Gateway
allow remote attackers to cause a denial of service and
possibly execute arbitrary code, as demonstrated by the
NISCC/OUSPG PROTOS test suite for the H.225 protocol.
Status: Candidate
Phase: Modified (20071113)
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
Reference: CERT:CA-2004-01
Reference:
URL:http://www.cert.org/advisories/CA-2004-01.html
Reference: CERT-VN:VU#749342
Reference:
URL:http://www.kb.cert.org/vuls/id/749342
Reference: BID:9406
Reference:
URL:http://www.securityfocus.com/bid/9406
Reference: SECTRACK:1008687
Reference:
URL:http://www.securitytracker.com/id?1008687
Votes:
ACCEPT(3) Green, Baker, Armstrong
NOOP(3) Wall, Cole, Cox
Name: CVE-2004-0057
Description:
The rawprint function in the ISAKMP decoding routines
(print-isakmp.c) for tcpdump 3.8.1 and earlier allows
remote attackers to cause a denial of service
(segmentation fault) via malformed ISAKMP packets that
cause invalid "len" or "loc" values to be used in a
loop, a different vulnerability than CVE-2003-0989.
Status: Candidate
Phase: Modified (20071113)
Reference: MLIST:[tcpdump-workers] multiple
vulnerabilities in tcpdump 3.8.1
Reference:
URL:http://marc.theaimsgroup.com/?l=tcpdump-workers&m=107325073018070&w=2
Reference: APPLE:APPLE-SA-2004-02-23
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: FEDORA:FLSA:1222
Reference:
URL:http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html
Reference: REDHAT:RHSA-2004:007
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-007.html
Reference: REDHAT:RHSA-2004:008
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-008.html
Reference: DEBIAN:DSA-425
Reference:
URL:http://www.debian.org/security/2004/dsa-425
Reference: MANDRAKE:MDKSA-2004:008
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:008
Reference: SGI:20040103-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
Reference: BUGTRAQ:20040131 [FLSA-2004:1222]
Updated tcpdump resolves security vulnerabilites (resend
with correct paths)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577418225627&w=2
Reference: SGI:20040202-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: CERT-VN:VU#174086
Reference:
URL:http://www.kb.cert.org/vuls/id/174086
Reference: BID:9423
Reference:
URL:http://www.securityfocus.com/bid/9423
Reference: OVAL:oval:org.mitre.oval:def:851
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851
Reference: OVAL:oval:org.mitre.oval:def:854
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854
Reference: SECTRACK:1008716
Reference:
URL:http://www.securitytracker.com/id?1008716
Reference: SECUNIA:10636
Reference:
URL:http://secunia.com/advisories/10636
Reference: XF:tcpdump-rawprint-isakmp-dos(14837)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14837
Votes:
ACCEPT(6) Green, Wall, Baker, Cole, Armstrong, Cox
NOOP(1) Christey
Voter Comments:
Christey> SCO:SCOSA-2004.9
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt
Name: CVE-2004-0058
Description:
Antivir / Linux 2.0.9-9, and possibly earlier versions,
allows local users to overwrite arbitrary files via a
symlink attack on the .pid_antivir_$$ temporary file.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040113 symlink vul for
Antivir / Linux Version 2.0.9-9 (maybe lower)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107402026023763&w=2
Reference: OSVDB:3496
Reference: URL:http://www.osvdb.org/3496
Reference: SECTRACK:1008702
Reference:
URL:http://www.securitytracker.com/id?1008702
Reference: SECUNIA:10620
Reference:
URL:http://secunia.com/advisories/10620
Reference: XF:antivir-tmpfile-insecure(14214)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14214
Votes:
ACCEPT(1) Baker
NOOP(4) Wall, Cole, Armstrong, Cox
REVIEWING(1) Green
Name: CVE-2004-0059
Description:
Directory traversal vulnerability in upload capability
of WWW File Share Pro 2.42 and earlier allows remote
attackers to overwrite arbitrary files via .. (dot dot)
sequences in the filename parameter of a
Content-Disposition: header.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 Multiple
vulnerabilities in WWW Fileshare Pro <= 2.42
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411794303201&w=2
Reference: SECTRACK:1008779
Reference:
URL:http://www.securitytracker.com/id?1008779
Votes:
ACCEPT(2) Baker, Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0060
Description:
WWW File Share Pro 2.42 and earlier allows remote
attackers to cause a denial of service (crash) via a
large POST request.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 Multiple
vulnerabilities in WWW Fileshare Pro <= 2.42
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411794303201&w=2
Reference: SECTRACK:1008779
Reference:
URL:http://www.securitytracker.com/id?1008779
Votes:
ACCEPT(2) Green, Baker
NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
Green> Acknowledged in 2.46 release notes
Name: CVE-2004-0061
Description:
WWW File Share Pro 2.42 and earlier allows remote
attackers to bypass directory access restrictions via
(1) a URL with a trailing . (dot), or (2) a URI with a
leading slash or backslash character.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 Multiple
vulnerabilities in WWW Fileshare Pro <= 2.42
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411794303201&w=2
Reference: SECTRACK:1008779
Reference:
URL:http://www.securitytracker.com/id?1008779
Votes:
ACCEPT(2) Green, Baker
NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
Green> Ack'ed in 2.46 release notes
Name: CVE-2004-0062
Description:
Integer overflow in the rnd arithmetic rounding function
for various versions of FishCart before 3.1 allows
remote attackers to "cause negative totals" via an order
with a large quantity.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 FishCart Integer
Overflow / Rounding Error
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411850203994&w=2
Reference: SECTRACK:1008731
Reference:
URL:http://www.securitytracker.com/id?1008731
Votes:
ACCEPT(1) Baker
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0064
Description:
The SuSEconfig.gnome-filesystem script for YaST in SuSE
9.0 allows local users to overwrite arbitrary files via
a symlink attack on files within the
tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary
directory.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040113 SuSE linux 9.0 YaST
config Skribt [exploit]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107402658600437&w=2
Reference: BID:9411
Reference:
URL:http://www.securityfocus.com/bid/9411
Reference: OSVDB:3460
Reference: URL:http://www.osvdb.org/3460
Reference: SECTRACK:1008703
Reference:
URL:http://www.securitytracker.com/id?1008703
Reference: SECUNIA:10623
Reference:
URL:http://secunia.com/advisories/10623
Votes:
ACCEPT(2) Baker, Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0065
Description:
Multiple SQL injection vulnerabilities in phpGedView
before 2.65 allow remote attackers to execute arbitrary
SQL via (1) timeline.php and (2) placelist.php.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040112 More phpGedView
Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107394912715478&w=2
Reference: BID:11910
Reference:
URL:http://www.securityfocus.com/bid/11910
Reference: BID:11925
Reference:
URL:http://www.securityfocus.com/bid/11925
Votes:
ACCEPT(4) Williams, Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Voter Comments:
Williams> http://sourceforge.net/project/showfiles.php?group_id=55456
Name: CVE-2004-0066
Description:
phpGedView before 2.65 allows remote attackers to obtain
the absolute path of the web server via malformed
parameters to (1) indilist.php, (2) famlist.php, (3)
placelist.php, (4) imageview.php, (5) timeline.php, (6)
clippings.php, (7) login.php, and (8) gdbi.php.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040112 More phpGedView
Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107394912715478&w=2
Reference: OSVDB:3464
Reference: URL:http://www.osvdb.org/3464
Reference: XF:phpgedview-path-disclosure(14215)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14215
Votes:
ACCEPT(3) Williams, Baker, Armstrong
NOOP(3) Wall, Cole, Cox
Voter Comments:
Williams> http://sourceforge.net/project/showfiles.php?group_id=55456
Name: CVE-2004-0067
Description:
Multiple cross-site scripting (XSS) vulnerabilities in
phpGedView before 2.65 allow remote attackers to inject
arbitrary HTML or web script via (1) descendancy.php,
(2) index.php, (3) individual.php, (4) login.php, (5)
relationship.php, (6) source.php, (7) imageview.php, (8)
calendar.php, (9) gedrecord.php, (10) login.php, and
(11) gdbi_interface.php. NOTE: some aspects of vector 10
were later reported to affect 4.1.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040112 More phpGedView
Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107394912715478&w=2
Reference: BUGTRAQ:20070827 PhpGedView login page
multiple XSS
Reference:
URL:http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded
Reference: BID:11868
Reference:
URL:http://www.securityfocus.com/bid/11868
Reference: BID:11880
Reference:
URL:http://www.securityfocus.com/bid/11880
Reference: BID:11882
Reference:
URL:http://www.securityfocus.com/bid/11882
Reference: BID:11888
Reference:
URL:http://www.securityfocus.com/bid/11888
Reference: BID:11890
Reference:
URL:http://www.securityfocus.com/bid/11890
Reference: BID:11891
Reference:
URL:http://www.securityfocus.com/bid/11891
Reference: BID:11894
Reference:
URL:http://www.securityfocus.com/bid/11894
Reference: BID:11903
Reference:
URL:http://www.securityfocus.com/bid/11903
Reference: BID:11904
Reference:
URL:http://www.securityfocus.com/bid/11904
Reference: BID:11905
Reference:
URL:http://www.securityfocus.com/bid/11905
Reference: BID:11906
Reference:
URL:http://www.securityfocus.com/bid/11906
Reference: BID:11907
Reference:
URL:http://www.securityfocus.com/bid/11907
Reference: FRSIRT:ADV-2007-2995
Reference:
URL:http://www.frsirt.com/english/advisories/2007/2995
Reference: OSVDB:3473
Reference: URL:http://www.osvdb.org/3473
Reference: OSVDB:3474
Reference: URL:http://www.osvdb.org/3474
Reference: OSVDB:3475
Reference: URL:http://www.osvdb.org/3475
Reference: OSVDB:3476
Reference: URL:http://www.osvdb.org/3476
Reference: OSVDB:3477
Reference: URL:http://www.osvdb.org/3477
Reference: OSVDB:3478
Reference: URL:http://www.osvdb.org/3478
Reference: SECTRACK:1018613
Reference:
URL:http://securitytracker.com/id?1018613
Reference: SECUNIA:26628
Reference:
URL:http://secunia.com/advisories/26628
Reference: XF:phpgedview-login-xss(36285)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/36285
Reference: XF:phpgedview-multiple-xss(14212)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14212
Votes:
ACCEPT(3) Williams, Baker, Armstrong
NOOP(3) Wall, Cole, Cox
Voter Comments:
Williams> http://sourceforge.net/project/showfiles.php?group_id=55456
Name: CVE-2004-0069
Description:
Format string vulnerability in HD Soft Windows FTP
Server 1.6 and earlier allows remote attackers to
execute arbitrary code via format string specifiers in
the username, which is processed by the wscanf function.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040108 Windows FTP Server
Format String Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107367110805273&w=2
Reference: BUGTRAQ:20040113 exploit for HD Soft
Windows FTP Server 1.6
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107401398014761&w=2
Reference: BID:9385
Reference:
URL:http://www.securityfocus.com/bid/9385
Reference: SECTRACK:1008658
Reference:
URL:http://www.securitytracker.com/id?1008658
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(3) Williams, Cole, Cox
REVIEWING(1) Wall
Voter Comments:
Williams> insufficient data.
Armstrong> Add reference: http://www.securiteam.com/exploits/5TP0C1FBPS.html
Name: CVE-2004-0071
Description:
Directory traversal vulnerability in buildManPage in
class.manpagelookup.php for PHP Man Page Lookup 1.2.0
allows remote attackers to read arbitrary files via the
command parameter ($cmd variable) to index.php.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040110 PHP Manpage lookup
directory transversal / file disclosing
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107392764118403&w=2
Reference: BID:9395
Reference:
URL:http://www.securityfocus.com/bid/9395
Reference: SECTRACK:1008689
Reference:
URL:http://www.securitytracker.com/id?1008689
Reference:
XF:manpagelookup-directory-traversal(14203)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14203
Votes:
ACCEPT(2) Baker, Armstrong
MODIFY(1) Williams
NOOP(3) Wall, Cole, Cox
Voter Comments:
Williams> contacted vendor. affects v1.2.0. fixed in v1.3.0.
http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php
http://php.amnuts.com/forums/viewtopic.php?t=70
Name: CVE-2004-0072
Description:
Directory traversal vulnerability in Accipiter Direct
Server 6.0 allows remote attackers to read arbitrary
files via encoded \.. (backslash .., "%5c%2e%2e")
sequences in an HTTP request.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040109 Directory Traversal
in Accipiter Direct Server 6.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107392576215418&w=2
Reference: FULLDISC:20040109 Directory Traversal
in Accipiter Direct Server 6.0
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html
Reference: OSVDB:3433
Reference: URL:http://www.osvdb.org/3433
Reference: SECUNIA:10600
Reference:
URL:http://secunia.com/advisories/10600
Reference:
XF:accipterdirectserver-directory-traversal(14198)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14198
Reference: BID:9389
Reference:
URL:http://www.securityfocus.com/bid/9389
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
Williams> insufficient data.
Name: CVE-2004-0073
Description:
PHP remote file inclusion vulnerability in (1)
config.php and (2) config_page.php for EasyDynamicPages
2.0 allows remote attackers to execute arbitrary PHP
code by modifying the edp_relative_path parameter to
reference a URL on a remote web server that contains a
malicious serverdata.php script.
Status: Candidate
Phase: Modified (20060907)
Reference: BUGTRAQ:20040102 include() vuln in
EasyDynamicPages v.2.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107307457327707&w=2
Reference: BID:9338
Reference:
URL:http://www.securityfocus.com/bid/9338
Reference: OSVDB:3318
Reference: URL:http://www.osvdb.org/3318
Reference: OSVDB:3408
Reference: URL:http://www.osvdb.org/3408
Reference: SECTRACK:1008584
Reference:
URL:http://securitytracker.com/id?1008584
Reference: SECUNIA:10535
Reference:
URL:http://secunia.com/advisories/10535
Reference:
XF:easydynamicpages-php-file-include(14136)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14136
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
Williams> insufficient data.
Name: CVE-2004-0074
Description:
Multiple buffer overflows in xsok 1.02 allows local
users to gain privileges via (1) a long LANG environment
variable, or (2) a long -xsokdir command line argument,
a different vulnerability than CVE-2003-0949.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040102 xsok local games
exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107307407027259&w=2
Reference: BUGTRAQ:20040103 xsok local games
exploit (2)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107332542918529&w=2
Reference: BID:9352
Reference:
URL:http://www.securityfocus.com/bid/9352
Reference: BID:9341
Reference:
URL:http://www.securityfocus.com/bid/9341
Reference: XF:xsok-lang-bo(14910)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14910
Reference: XF:xsok-long-xsokdir-bo(14906)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14906
Votes:
ACCEPT(3) Williams, Baker, Armstrong
NOOP(3) Wall, Cole, Cox
Voter Comments:
Williams> DSA-405-1
Name: CVE-2004-0076
Description:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.
ConsultIDs: none. Reason: This candidate was removed
from consideration by its Candidate Numbering Authority.
Notes: none.
Status: Candidate
Phase: Assigned (20040119)
Votes:
Name: CVE-2004-0079
Description:
The do_change_cipher_spec function in OpenSSL 0.9.6c to
0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to
cause a denial of service (crash) via a crafted SSL/TLS
handshake that triggers a null dereference.
Status: Candidate
Phase: Assigned (20040119)
Reference: BUGTRAQ:20040317 New OpenSSL releases
fix denial of service attacks [17 March 2004]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107953412903636&w=2
Reference:
CONFIRM:http://www.openssl.org/news/secadv_20040317.txt
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/224012/index.htm
Reference:
CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm
Reference: CISCO:20040317 Cisco OpenSSL
Implementation Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
Reference: APPLE:APPLE-SA-2005-08-15
Reference:
URL:http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
Reference: APPLE:APPLE-SA-2005-08-17
Reference:
URL:http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
Reference: CONECTIVA:CLA-2004:834
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
Reference: DEBIAN:DSA-465
Reference:
URL:http://www.debian.org/security/2004/dsa-465
Reference: ENGARDE:ESA-20040317-003
Reference:
URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html
Reference: FEDORA:FEDORA-2004-095
Reference:
URL:http://fedoranews.org/updates/FEDORA-2004-095.shtml
Reference: FEDORA:FEDORA-2005-1042
Reference:
URL:http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html
Reference: FREEBSD:FreeBSD-SA-04:05
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc
Reference: GENTOO:GLSA-200403-03
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-03.xml
Reference: HP:SSRT4717
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403806509920&w=2
Reference: MANDRAKE:MDKSA-2004:023
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:023
Reference: NETBSD:NetBSD-SA2004-005
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc
Reference: REDHAT:RHSA-2004:120
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-120.html
Reference: REDHAT:RHSA-2004:121
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-121.html
Reference: REDHAT:RHSA-2004:139
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-139.html
Reference: REDHAT:RHSA-2005:830
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-830.html
Reference: REDHAT:RHSA-2005:829
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-829.html
Reference: SCO:SCOSA-2004.10
Reference:
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt
Reference: SLACKWARE:SSA:2004-077
Reference:
URL:http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961
Reference: SUSE:SuSE-SA:2004:007
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_07_openssl.html
Reference: SUNALERT:57524
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
Reference: TRUSTIX:2004-0012
Reference:
URL:http://www.trustix.org/errata/2004/0012
Reference:
CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference:
CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00045.html
Reference: CERT:TA04-078A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-078A.html
Reference: CERT-VN:VU#288574
Reference:
URL:http://www.kb.cert.org/vuls/id/288574
Reference: CIAC:O-101
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-101.shtml
Reference: BID:9899
Reference:
URL:http://www.securityfocus.com/bid/9899
Reference: OVAL:oval:org.mitre.oval:def:2621
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2621
Reference: OVAL:oval:org.mitre.oval:def:870
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:870
Reference: OVAL:oval:org.mitre.oval:def:975
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:975
Reference: SECUNIA:11139
Reference:
URL:http://secunia.com/advisories/11139
Reference: SECUNIA:17401
Reference:
URL:http://secunia.com/advisories/17401
Reference: SECUNIA:17381
Reference:
URL:http://secunia.com/advisories/17381
Reference: SECUNIA:17398
Reference:
URL:http://secunia.com/advisories/17398
Reference: SECUNIA:18247
Reference:
URL:http://secunia.com/advisories/18247
Reference:
XF:openssl-dochangecipherspec-dos(15505)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15505
Votes:
Name: CVE-2004-0081
Description:
OpenSSL 0.9.6 before 0.9.6d does not properly handle
unknown message types, which allows remote attackers to
cause a denial of service (infinite loop), as
demonstrated using the Codenomicon TLS Test Tool.
Status: Candidate
Phase: Assigned (20040119)
Reference: BUGTRAQ:20040317 Re: New OpenSSL
releases fix denial of service attacks [17 March 2004]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107955049331965&w=2
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/224012/index.htm
Reference: CISCO:20040317 Cisco OpenSSL
Implementation Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
Reference: CONECTIVA:CLA-2004:834
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
Reference: DEBIAN:DSA-465
Reference:
URL:http://www.debian.org/security/2004/dsa-465
Reference: ENGARDE:ESA-20040317-003
Reference:
URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html
Reference: FEDORA:FEDORA-2004-095
Reference:
URL:http://fedoranews.org/updates/FEDORA-2004-095.shtml
Reference: GENTOO:GLSA-200403-03
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-03.xml
Reference: REDHAT:RHSA-2004:119
Reference:
URL:http://rhn.redhat.com/errata/RHSA-2004-119.html
Reference: REDHAT:RHSA-2004:120
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-120.html
Reference: REDHAT:RHSA-2004:121
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-121.html
Reference: REDHAT:RHSA-2004:139
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-139.html
Reference: SCO:SCOSA-2004.10
Reference:
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt
Reference: SGI:20040304-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc
Reference: SUNALERT:57524
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
Reference: TRUSTIX:2004-0012
Reference:
URL:http://www.trustix.org/errata/2004/0012
Reference: BUGTRAQ:20040508 [FLSA-2004:1395]
Updated OpenSSL resolves security vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403850228012&w=2
Reference: CERT:TA04-078A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-078A.html
Reference: CERT-VN:VU#465542
Reference:
URL:http://www.kb.cert.org/vuls/id/465542
Reference: BID:9899
Reference:
URL:http://www.securityfocus.com/bid/9899
Reference: OVAL:oval:org.mitre.oval:def:871
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:871
Reference: OVAL:oval:org.mitre.oval:def:902
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:902
Reference: SECUNIA:11139
Reference:
URL:http://secunia.com/advisories/11139
Reference: XF:openssl-tls-dos(15509)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15509
Votes:
Name: CVE-2004-0083
Description:
Buffer overflow in ReadFontAlias from dirfile.c of
XFree86 4.1.0 through 4.3.0 allows local users and
remote attackers to execute arbitrary code via a font
alias file (font.alias) with a long token, a different
vulnerability than CVE-2004-0084 and CVE-2004-0106.
Status: Candidate
Phase: Modified (20061101)
Reference: BUGTRAQ:20040210
iDEFENSESecurityAdvisory02.10.04:
XFree86FontInformationFileBufferOverflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107644835523678&w=2
Reference:
MISC:http://www.idefense.com/application/poi/display?id=72
Reference: BUGTRAQ:20040211 XFree86 vulnerability
exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107653324115914&w=2
Reference:
CONFIRM:http://www.xfree86.org/cvs/changes
Reference: CONECTIVA:CLA-2004:821
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000821
Reference: DEBIAN:DSA-443
Reference:
URL:http://www.debian.org/security/2004/dsa-443
Reference: FEDORA:FLSA:2314
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110979666528890&w=2
Reference: REDHAT:RHSA-2004:059
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-059.html
Reference: REDHAT:RHSA-2004:060
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-060.html
Reference: REDHAT:RHSA-2004:061
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-061.html
Reference: SLACKWARE:SSA:2004-043
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
Reference: SUNALERT:57768
Reference:
URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1
Reference: SUSE:SuSE-SA:2004:006
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_06_xf86.html
Reference: MANDRAKE:MDKSA-2004:012
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:012
Reference: GENTOO:GLSA-200402-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200402-02.xml
Reference: CERT-VN:VU#820006
Reference:
URL:http://www.kb.cert.org/vuls/id/820006
Reference: BID:9636
Reference:
URL:http://www.securityfocus.com/bid/9636
Reference: OVAL:oval:org.mitre.oval:def:806
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806
Reference: OVAL:oval:org.mitre.oval:def:830
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830
Reference: XF:xfree86-fontalias-bo(15130)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15130
Votes:
ACCEPT(5) Wall, Baker, Cole, Armstrong, Cox
NOOP(1) Christey
Voter Comments:
Christey> CIAC:O-081
URL:http://www.ciac.org/ciac/bulletins/o-081.shtml
IMMUNIX:IMNX-2004-73-002-01
URL:http://www.securityfocus.com/advisories/6328
BID:9636
URL:http://www.securityfocus.com/bid/9636
Christey> Normalize Gentoo reference
Christey> SCO:SCOSA-2004.2
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt
SCO:SCOSA-2004.3
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt
Name: CVE-2004-0084
Description:
Buffer overflow in the ReadFontAlias function in XFree86
4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered
function, allows local or remote authenticated users to
execute arbitrary code via a malformed entry in the font
alias (font.alias) file, a different vulnerability than
CVE-2004-0083 and CVE-2004-0106.
Status: Candidate
Phase: Modified (20061101)
Reference: BUGTRAQ:20040212 iDEFENSE Security
Advisory 02.11.04: XFree86 Font Information File Buffer
Overflow II
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107662833512775&w=2
Reference:
MISC:http://www.idefense.com/application/poi/display?id=73
Reference: CONECTIVA:CLA-2004:821
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000821
Reference: DEBIAN:DSA-443
Reference:
URL:http://www.debian.org/security/2004/dsa-443
Reference: FEDORA:FLSA:2314
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110979666528890&w=2
Reference: REDHAT:RHSA-2004:059
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-059.html
Reference: REDHAT:RHSA-2004:060
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-060.html
Reference: REDHAT:RHSA-2004:061
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-061.html
Reference: SLACKWARE:SSA:2004-043
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
Reference: SUNALERT:57768
Reference:
URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1
Reference: SUSE:SuSE-SA:2004:006
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_06_xf86.html
Reference: MANDRAKE:MDKSA-2004:012
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:012
Reference: CERT-VN:VU#667502
Reference:
URL:http://www.kb.cert.org/vuls/id/667502
Reference: BID:9652
Reference:
URL:http://www.securityfocus.com/bid/9652
Reference: OVAL:oval:org.mitre.oval:def:807
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807
Reference: OVAL:oval:org.mitre.oval:def:831
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831
Reference:
XF:xfree86-copyisolatin1lLowered-bo(15200)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15200
Votes:
ACCEPT(3) Baker, Armstrong, Cox
NOOP(2) Christey, Cole
REVIEWING(1) Wall
Voter Comments:
Christey> CIAC:O-081
URL:http://www.ciac.org/ciac/bulletins/o-081.shtml
IMMUNIX:IMNX-2004-73-002-01
URL:http://www.securityfocus.com/advisories/6328
BID:9652
URL:http://www.securityfocus.com/bid/9652
Christey> SCO:SCOSA-2004.2
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt
SCO:SCOSA-2004.3
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt
Name: CVE-2004-0085
Description:
Unknown vulnerability in the Mail application for Mac OS
X 10.1.5 and 10.2.8 with unknown impact, a different
vulnerability than CVE-2004-0086.
Status: Candidate
Phase: Modified (20050813)
Reference: APPLE:APPLE-SA-2004-01-26
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference:
URL:http://www.securityfocus.com/bid/9504
Reference: XF:macosx-mail-undisclosed(14992)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14992
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0086
Description:
Unknown vulnerability in the Mail application for Mac OS
X 10.3.2 has unknown impact and attack vectors, a
different vulnerability than CVE-2004-0085.
Status: Candidate
Phase: Modified (20050813)
Reference: APPLE:APPLE-SA-2004-01-26
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference:
URL:http://www.securityfocus.com/bid/9504
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0087
Description:
The System Configuration subsystem in Mac OS 10.2.8 and
10.3.2 allows local users to modify network settings, a
different vulnerability than CVE-2004-0088.
Status: Candidate
Phase: Modified (20071113)
Reference: APPLE:APPLE-SA-2004-01-26
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference:
URL:http://www.securityfocus.com/bid/9504
Reference: OSVDB:6819
Reference: URL:http://www.osvdb.org/6819
Reference:
XF:macosx-configd-file-manipulation(14997)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14997
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0088
Description:
The System Configuration subsystem in Mac OS 10.2.8
allows local users to modify network settings, a
different vulnerability than CVE-2004-0087.
Status: Candidate
Phase: Modified (20071113)
Reference: APPLE:APPLE-SA-2004-01-26
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference:
URL:http://www.securityfocus.com/bid/9504
Reference: OSVDB:6820
Reference: URL:http://www.osvdb.org/6820
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0090
Description:
Unknown vulnerability in Windows File Sharing for Mac OS
X 10.1.5 through 10.3.2 does not "shutdown properly,"
which has unknown impact and attack vectors.
Status: Candidate
Phase: Assigned (20040120)
Reference: APPLE:APPLE-SA-2004-01-26
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: AUSCERT:ESB-2004.0072
Reference:
URL:http://www.auscert.org.au/render.html?it=3791&cid=1
Reference: BID:9504
Reference:
URL:http://www.securityfocus.com/bid/9504
Reference: SECUNIA:10723
Reference:
URL:http://secunia.com/advisories/10723/
Votes:
Name: CVE-2004-0091
Description:
** DISPUTED ** NOTE: this issue has been disputed by the
vendor. Cross-site scripting (XSS) vulnerability in
register.php for unknown versions of vBulletin allows
remote attackers to inject arbitrary HTML or web script
via the reg_site (or possibly regsite) parameter. NOTE:
the vendor has disputed this issue, saying "There is no
hidden field called 'reg_site', nor any $reg_site
variable anywhere in the vBulletin 2 or vBulletin 3
source code or templates, nor has it ever existed. We
can only assume that this vulnerability was found in a
site running code modified from that supplied by
Jelsoft."
Status: Candidate
Phase: Modified (20051208)
Reference: BUGTRAQ:20040120 vBulletin Security
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107462349324945&w=2
Reference: VULN-DEV:20040120 vBulletin Security
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=107462499927040&w=2
Reference: VULN-DEV:20040120 Re: vBulletin
Security Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=107478592401619&w=2
Reference: VULN-DEV:20040123 RE: vBulletin
Security Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=107488880317647&w=2
Reference: SECTRACK:1008780
Reference:
URL:http://securitytracker.com/id?1008780
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
REVIEWING(1) Green
Name: CVE-2004-0092
Description:
Unknown vulnerability in Safari web browser in Mac OS X
10.2.8 and 10.3.2, with unknown impact.
Status: Candidate
Phase: Modified (20040812)
Reference: APPLE:APPLE-SA-2004-01-26
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference:
URL:http://www.securityfocus.com/bid/9504
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0097
Description:
Multiple vulnerabilities in PWLib before 1.6.0 allow
remote attackers to cause a denial of service and
possibly execute arbitrary code, as demonstrated by the
NISCC/OUSPG PROTOS test suite for the H.225 protocol.
Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-448
Reference:
URL:http://www.debian.org/security/2004/dsa-448
Reference: REDHAT:RHSA-2004:047
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-047.html
Reference: CERT:CA-2004-01
Reference:
URL:http://www.cert.org/advisories/CA-2004-01.html
Reference: CERT-VN:VU#749342
Reference:
URL:http://www.kb.cert.org/vuls/id/749342
Reference: BID:9406
Reference:
URL:http://www.securityfocus.com/bid/9406
Reference: XF:pwlib-message-dos(15202)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15202
Reference: OVAL:oval:org.mitre.oval:def:803
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803
Reference: OVAL:oval:org.mitre.oval:def:826
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
MODIFY(1) Cox
NOOP(1) Christey
Voter Comments:
Cox> Addref: REDHAT:RHSA-2004:048
Be useful to mention OpenH323 and/or H.323 in this text to aid
searching on this issue
Christey> BUGTRAQ:20040409 [ GLSA 200404-11 ] Multiple Vulnerabilities in pwlib
Name: CVE-2004-0098
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040128)
Votes:
Name: CVE-2004-0100
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040129)
Votes:
Name: CVE-2004-0101
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040129)
Votes:
Name: CVE-2004-0102
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040129)
Votes:
Name: CVE-2004-0103
Description:
crawl before 4.0.0 beta23 does not properly "apply a
size check" when copying a certain environment variable,
which may allow local users to gain privileges, possibly
as a result of a buffer overflow.
Status: Candidate
Phase: Modified (20050808)
Reference: DEBIAN:DSA-432
Reference:
URL:http://www.debian.org/security/2004/dsa-432
Reference: BID:9566
Reference:
URL:http://www.securityfocus.com/bid/9566
Reference: SECUNIA:10788
Reference:
URL:http://secunia.com/advisories/10788/
Reference: XF:crawl-long-environment-bo(15032)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15032
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0104
Description:
Multiple format string vulnerabilities in Metamail 2.7
and earlier allow remote attackers to execute arbitrary
code.
Status: Candidate
Phase: Modified (20050808)
Reference: BUGTRAQ:20040218 metamail format
string bugs and buffer overflows
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107713476911429&w=2
Reference: VULNWATCH:20040218 metamail format
string bugs and buffer overflows
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html
Reference: DEBIAN:DSA-449
Reference:
URL:http://www.debian.org/security/2004/dsa-449
Reference: MANDRAKE:MDKSA-2004:014
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:014
Reference: REDHAT:RHSA-2004:073
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-073.html
Reference: SLACKWARE:SSA:2004-049
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404734
Reference: CERT-VN:VU#518518
Reference:
URL:http://www.kb.cert.org/vuls/id/518518
Reference: CIAC:O-083
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-083.shtml
Reference: BID:9692
Reference:
URL:http://www.securityfocus.com/bid/9692
Reference: SECUNIA:10908
Reference:
URL:http://secunia.com/advisories/10908
Reference:
XF:metamail-contenttype-format-string(15245)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15245
Reference:
XF:metamail-printheader-format-string(15259)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15259
Votes:
ACCEPT(5) Wall, Baker, Cole, Armstrong, Cox
Name: CVE-2004-0105
Description:
Multiple buffer overflows in Metamail 2.7 and earlier
allow remote attackers to execute arbitrary code.
Status: Candidate
Phase: Modified (20050808)
Reference: BUGTRAQ:20040218 metamail format
string bugs and buffer overflows
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107713476911429&w=2
Reference: VULNWATCH:20040218 metamail format
string bugs and buffer overflows
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html
Reference: DEBIAN:DSA-449
Reference:
URL:http://www.debian.org/security/2004/dsa-449
Reference: MANDRAKE:MDKSA-2004:014
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:014
Reference: REDHAT:RHSA-2004:073
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-073.html
Reference: SLACKWARE:SSA:2004-049
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404734
Reference: CERT-VN:VU#513062
Reference:
URL:http://www.kb.cert.org/vuls/id/513062
Reference: CIAC:O-083
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-083.shtml
Reference: BID:9692
Reference:
URL:http://www.securityfocus.com/bid/9692
Reference: SECUNIA:10908
Reference:
URL:http://secunia.com/advisories/10908
Reference:
XF:metamail-printheader-nonascii-bo(15247)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15247
Reference:
XF:metamail-splitmail-subject-bo(15258)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15258
Votes:
ACCEPT(5) Wall, Baker, Cole, Armstrong, Cox
Name: CVE-2004-0106
Description:
Multiple unknown vulnerabilities in XFree86 4.1.0 to
4.3.0, related to improper handling of font files, a
different set of vulnerabilities than CVE-2004-0083 and
CVE-2004-0084.
Status: Candidate
Phase: Modified (20061101)
Reference: CONECTIVA:CLA-2004:821
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000821
Reference: DEBIAN:DSA-443
Reference:
URL:http://www.debian.org/security/2004/dsa-443
Reference: FEDORA:FLSA:2314
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110979666528890&w=2
Reference: REDHAT:RHSA-2004:059
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-059.html
Reference: REDHAT:RHSA-2004:060
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-060.html
Reference: REDHAT:RHSA-2004:061
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-061.html
Reference: SLACKWARE:SSA:2004-043
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
Reference: SUSE:SuSE-SA:2004:006
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_06_xf86.html
Reference: MANDRAKE:MDKSA-2004:012
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:012
Reference:
XF:xfree86-multiple-font-improper-handling(15206)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15206
Reference: OVAL:oval:org.mitre.oval:def:809
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809
Reference: OVAL:oval:org.mitre.oval:def:832
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832
Votes:
ACCEPT(3) Baker, Armstrong, Cox
NOOP(2) Christey, Cole
REVIEWING(1) Wall
Voter Comments:
Christey> CIAC:O-081
URL:http://www.ciac.org/ciac/bulletins/o-081.shtml
IMMUNIX:IMNX-2004-73-002-01
URL:http://www.securityfocus.com/advisories/6328
BID:9655
URL:http://www.securityfocus.com/bid/9655
TURBO:TLSA-2004-5
URL:http://www.turbolinux.com/security/2004/TLSA-2004-5.txt
Christey> SCO:SCOSA-2004.2
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt
SCO:SCOSA-2004.3
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt
Name: CVE-2004-0107
Description:
The (1) post and (2) trigger scripts in sysstat 4.0.7
and earlier allow local users to overwrite arbitrary
files via symlink attacks on temporary files, a
different vulnerability than CVE-2004-0108.
Status: Candidate
Phase: Modified (20061101)
Reference: REDHAT:RHSA-2004:053
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-053.html
Reference: REDHAT:RHSA-2004:093
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-093.html
Reference: SGI:20040302-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc
Reference: CIAC:O-097
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-097.shtml
Reference: BID:9838
Reference:
URL:http://www.securityfocus.com/bid/9838
Reference: OSVDB:6884
Reference: URL:http://www.osvdb.org/6884
Reference: OVAL:oval:org.mitre.oval:def:849
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:849
Reference: OVAL:oval:org.mitre.oval:def:862
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:862
Reference: XF:sysstat-post-trigger-symlink(15428)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15428
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
MODIFY(2) Frech, Cox
NOOP(1) Christey
Voter Comments:
Frech> XF:sysstat-post-trigger-symlink(15428)
http://xforce.iss.net/xforce/xfdb/15428
Cox> This issue is in the vendor packaging of sysstat, not sysstat itself,
and does not apply to a particular version of upstream
sysstat. Suggest "trigger scripts in various vendors packaging of
syssstat allows local users..." or "in the Red Hat packaging of sysstat"
Christey> CIAC:O-097
URL:http://www.ciac.org/ciac/bulletins/o-097.shtml
XF:sysstat-post-trigger-symlink(15428)
URL:http://xforce.iss.net/xforce/xfdb/15428
BID:9838
URL:http://www.securityfocus.com/bid/9838
Christey> FEDORA:FEDORA-2004-1372
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1372
Name: CVE-2004-0109
Description:
Buffer overflow in the ISO9660 file system component for
Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users
with physical access to overflow kernel memory and
execute arbitrary code via a malformed CD containing a
long symbolic link entry.
Status: Candidate
Phase: Assigned (20040202)
Reference:
MISC:http://www.idefense.com/application/poi/display?id=101&type=vulnerabilities
Reference: CONECTIVA:CLA-2004:846
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-479
Reference:
URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference:
URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference:
URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference:
URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference:
URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference:
URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference:
URL:http://www.debian.org/security/2004/dsa-495
Reference: ENGARDE:ESA-20040428-004
Reference:
URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:105
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-105.html
Reference: REDHAT:RHSA-2004:106
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-106.html
Reference: REDHAT:RHSA-2004:166
Reference:
URL:http://rhn.redhat.com/errata/RHSA-2004-166.html
Reference: REDHAT:RHSA-2004:183
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-183.html
Reference: SGI:20040405-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc
Reference: SGI:20040504-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc
Reference: SUSE:SuSE-SA:2004:009
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_09_kernel.html
Reference: TRUSTIX:2004-0020
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference: TURBO:TLSA-2004-14
Reference:
URL:http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
Reference: CIAC:O-121
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-127
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: BID:10141
Reference:
URL:http://www.securityfocus.com/bid/10141
Reference: OVAL:oval:org.mitre.oval:def:940
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940
Reference: SECUNIA:11361
Reference:
URL:http://secunia.com/advisories/11361
Reference: SECUNIA:11362
Reference:
URL:http://secunia.com/advisories/11362
Reference: SECUNIA:11373
Reference:
URL:http://secunia.com/advisories/11373
Reference: SECUNIA:11429
Reference: SECUNIA:11464
Reference:
URL:http://secunia.com/advisories/11464
Reference: SECUNIA:11469
Reference:
URL:http://secunia.com/advisories/11469
Reference: SECUNIA:11470
Reference:
URL:http://secunia.com/advisories/11470
Reference: SECUNIA:11486
Reference:
URL:http://secunia.com/advisories/11486
Reference: SECUNIA:11494
Reference:
URL:http://secunia.com/advisories/11494
Reference: SECUNIA:11518
Reference:
URL:http://secunia.com/advisories/11518
Reference: SECUNIA:11626
Reference:
URL:http://secunia.com/advisories/11626
Reference: SECUNIA:11861
Reference:
URL:http://secunia.com/advisories/11861
Reference: SECUNIA:11891
Reference:
URL:http://secunia.com/advisories/11891
Reference: SECUNIA:11986
Reference:
URL:http://secunia.com/advisories/11986
Reference: SECUNIA:12003
Reference:
URL:http://secunia.com/advisories/12003
Reference: XF:linux-iso9660-bo(15866)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15866
Votes:
Name: CVE-2004-0110
Description:
Buffer overflow in the (1) nanohttp or (2) nanoftp
modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through
2.6.5 allow remote attackers to execute arbitrary code
via a long URL.
Status: Candidate
Phase: Modified (20070303)
Reference:
CONFIRM:http://www.xmlsoft.org/news.html
Reference: DEBIAN:DSA-455
Reference:
URL:http://www.debian.org/security/2004/dsa-455
Reference: GENTOO:GLSA-200403-01
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-01.xml
Reference: REDHAT:RHSA-2004:090
Reference:
URL:http://rhn.redhat.com/errata/RHSA-2004-090.html
Reference: REDHAT:RHSA-2004:091
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-091.html
Reference: BUGTRAQ:20040305 [OpenPKG-SA-2004.003]
OpenPKG Security Advisory (libxml)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107851606605420&w=2
Reference: BUGTRAQ:20040306 TSLSA-2004-0010 -
libxml2
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107860178228804&w=2
Reference: REDHAT:RHSA-2004:650
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-650.html
Reference: SUSE:SUSE-SR:2005:001
Reference:
URL:http://www.novell.com/linux/security/advisories/2005_01_sr.html
Reference: CERT-VN:VU#493966
Reference:
URL:http://www.kb.cert.org/vuls/id/493966
Reference: CIAC:O-086
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-086.shtml
Reference: BID:9718
Reference:
URL:http://www.securityfocus.com/bid/9718
Reference: SECUNIA:10958
Reference:
URL:http://secunia.com/advisories/10958/
Reference: OVAL:oval:org.mitre.oval:def:833
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833
Reference: OVAL:oval:org.mitre.oval:def:875
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875
Reference: XF:libxml2-nanohttp-bo(15301)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15301
Reference: XF:libxml2-nanoftp-bo(15302)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15302
Votes:
ACCEPT(6) Green, Wall, Baker, Cole, Armstrong, Cox
NOOP(1) Christey
Voter Comments:
Christey> CONECTIVA:CLA-2004:836
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000836
Christey> Add APPLE-SA-2004-04-05
CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00047.html
Green> VERIFIED-BY-SOMEONE-I-TRUST
Christey> Normalize Trustix references
Christey> FEDORA:FEDORA-2004-1324
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109035140702164&w=2
Name: CVE-2004-0112
Description:
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b,
and 0.9.7c, when using Kerberos ciphersuites, does not
properly check the length of Kerberos tickets during a
handshake, which allows remote attackers to cause a
denial of service (crash) via a crafted SSL/TLS
handshake that causes an out-of-bounds read.
Status: Candidate
Phase: Assigned (20040202)
Reference: BUGTRAQ:20040317 New OpenSSL releases
fix denial of service attacks [17 March 2004]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107953412903636&w=2
Reference:
CONFIRM:http://www.openssl.org/news/secadv_20040317.txt
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/224012/index.htm
Reference: APPLE:APPLE-SA-2005-08-15
Reference:
URL:http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
Reference: APPLE:APPLE-SA-2005-08-17
Reference:
URL:http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
Reference: CISCO:20040317 Cisco OpenSSL
Implementation Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
Reference: CONECTIVA:CLA-2004:834
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
Reference: GENTOO:GLSA-200403-03
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-03.xml
Reference: MANDRAKE:MDKSA-2004:023
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:023
Reference: NETBSD:NetBSD-SA2004-005
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc
Reference: REDHAT:RHSA-2004:120
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-120.html
Reference: REDHAT:RHSA-2004:121
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-121.html
Reference: SCO:SCOSA-2004.10
Reference:
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt
Reference: SLACKWARE:SSA:2004-077
Reference:
URL:http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961
Reference: SUSE:SuSE-SA:2004:007
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_07_openssl.html
Reference: SUNALERT:57524
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
Reference: TRUSTIX:2004-0012
Reference:
URL:http://www.trustix.org/errata/2004/0012
Reference: HP:SSRT4717
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403806509920&w=2
Reference:
CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference:
CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00045.html
Reference: CERT:TA04-078A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-078A.html
Reference: CERT-VN:VU#484726
Reference:
URL:http://www.kb.cert.org/vuls/id/484726
Reference: CIAC:O-101
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-101.shtml
Reference: BID:9899
Reference:
URL:http://www.securityfocus.com/bid/9899
Reference: OVAL:oval:org.mitre.oval:def:1049
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1049
Reference: OVAL:oval:org.mitre.oval:def:928
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:928
Reference: SECUNIA:11139
Reference:
URL:http://secunia.com/advisories/11139
Reference:
XF:openssl-kerberos-ciphersuites-dos(15508)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15508
Votes:
Name: CVE-2004-0116
Description:
An Activation function in the RPCSS Service involved
with DCOM activation for Microsoft Windows 2000, XP, and
2003 allows remote attackers to cause a denial of
service (memory consumption) via an activation request
with a large length field.
Status: Candidate
Phase: Assigned (20040203)
Reference: EEYE:AD20040413A
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD20040413A.html
Reference: MS:MS04-012
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-012.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#417052
Reference:
URL:http://www.kb.cert.org/vuls/id/417052
Reference: CIAC:O-115
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-115.shtml
Reference: BID:10127
Reference:
URL:http://www.securityfocus.com/bid/10127
Reference: OVAL:oval:org.mitre.oval:def:955
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:955
Reference: OVAL:oval:org.mitre.oval:def:957
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:957
Reference: OVAL:oval:org.mitre.oval:def:958
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:958
Reference: SECTRACK:1009758
Reference:
URL:http://securitytracker.com/alerts/2004/Apr/1009758.html
Reference: SECUNIA:11065
Reference:
URL:http://secunia.com/advisories/11065/
Reference: XF:win-rpcss-rpcmessage-dos(15708)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15708
Votes:
Name: CVE-2004-0117
Description:
Unknown vulnerability in the H.323 protocol
implementation in Windows 98, Windows 2000, Windows XP,
and Windows Server 2003 allows remote attackers to
execute arbitrary code.
Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#353956
Reference:
URL:http://www.kb.cert.org/vuls/id/353956
Reference: CIAC:O-114
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: OVAL:oval:org.mitre.oval:def:907
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:907
Reference: OVAL:oval:org.mitre.oval:def:946
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:946
Reference: OVAL:oval:org.mitre.oval:def:964
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:964
Reference: XF:win-h323-bo(15710)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15710
Votes:
Name: CVE-2004-0118
Description:
The component for the Virtual DOS Machine (VDM)
subsystem in Windows NT 4.0 and Windows 2000 does not
properly validate system structures, which allows local
users to access protected kernel memory and execute
arbitrary code.
Status: Candidate
Phase: Assigned (20040203)
Reference: FULLDISC:20040413 EEYE: Windows VDM
TIB Local Privilege Escalation
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html
Reference: EEYE:AD20040413E
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD20040413E.html
Reference: MS:MS04-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#783748
Reference:
URL:http://www.kb.cert.org/vuls/id/783748
Reference: CIAC:O-114
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10117
Reference:
URL:http://www.securityfocus.com/bid/10117
Reference: OVAL:oval:org.mitre.oval:def:1512
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1512
Reference: OVAL:oval:org.mitre.oval:def:1718
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1718
Reference: XF:win-vdm-gain-privileges(15714)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15714
Votes:
Name: CVE-2004-0119
Description:
The Negotiate Security Software Provider (SSP) interface
in Windows 2000, Windows XP, and Windows Server 2003,
allows remote attackers to cause a denial of service
(crash from null dereference) or execute arbitrary code
via a crafted SPNEGO NegTokenInit request during
authentication protocol selection.
Status: Candidate
Phase: Assigned (20040203)
Reference: VULNWATCH:20040414 NSFOCUS SA2004-01 :
DoS Vulnerability in Microsoft Windows SPNEGO Protocol
Decoding
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html
Reference: MS:MS04-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#638548
Reference:
URL:http://www.kb.cert.org/vuls/id/638548
Reference: CIAC:O-114
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10113
Reference:
URL:http://www.securityfocus.com/bid/10113
Reference: OVAL:oval:org.mitre.oval:def:1808
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1808
Reference: OVAL:oval:org.mitre.oval:def:1962
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1962
Reference: OVAL:oval:org.mitre.oval:def:1997
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1997
Reference: XF:win-spp-bo(15715)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15715
Votes:
Name: CVE-2004-0120
Description:
The Microsoft Secure Sockets Layer (SSL) library, as
used in Windows 2000, Windows XP, and Windows Server
2003, allows remote attackers to cause a denial of
service via malformed SSL messages.
Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#150236
Reference:
URL:http://www.kb.cert.org/vuls/id/150236
Reference: CIAC:O-114
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10115
Reference:
URL:http://www.securityfocus.com/bid/10115
Reference: OVAL:oval:org.mitre.oval:def:885
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:885
Reference: OVAL:oval:org.mitre.oval:def:886
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:886
Reference: OVAL:oval:org.mitre.oval:def:892
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:892
Reference: XF:ssl-message-dos(15712)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15712
Votes:
Name: CVE-2004-0123
Description:
Double free vulnerability in the ASN.1 library as used
in Windows NT 4.0, Windows 2000, Windows XP, and Windows
Server 2003, allows remote attackers to cause a denial
of service and possibly execute arbitrary code.
Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-011
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#255924
Reference:
URL:http://www.kb.cert.org/vuls/id/255924
Reference: CIAC:O-114
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10118
Reference:
URL:http://www.securityfocus.com/bid/10118
Reference: OVAL:oval:org.mitre.oval:def:1007
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1007
Reference: OVAL:oval:org.mitre.oval:def:1076
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1076
Reference: OVAL:oval:org.mitre.oval:def:924
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:924
Reference: XF:win-asn1-double-free(15713)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15713
Votes:
Name: CVE-2004-0124
Description:
The DCOM RPC interface for Microsoft Windows NT 4.0,
2000, XP, and Server 2003 allows remote attackers to
cause network communications via an "alter context" call
that contains additional data, aka the "Object Identity
Vulnerability."
Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-012
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-012.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#212892
Reference:
URL:http://www.kb.cert.org/vuls/id/212892
Reference: CIAC:O-115
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-115.shtml
Reference: BID:10121
Reference:
URL:http://www.securityfocus.com/bid/10121
Reference: OVAL:oval:org.mitre.oval:def:1041
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1041
Reference: OVAL:oval:org.mitre.oval:def:1062
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1062
Reference: OVAL:oval:org.mitre.oval:def:1066
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1066
Reference: OVAL:oval:org.mitre.oval:def:1072
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1072
Reference: SECUNIA:11065
Reference:
URL:http://secunia.com/advisories/11065/
Reference:
XF:win-objectidentifier-open-port(15711)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15711
Votes:
Name: CVE-2004-0125
Description:
The jail system call in FreeBSD 4.x before 4.10-RELEASE
does not verify that an attempt to manipulate routing
tables originated from a non-jailed process, which could
allow local users to modify the routing table.
Status: Candidate
Phase: Assigned (20040203)
Reference: FREEBSD:FreeBSD-SA-04:12
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc
Reference: BID:10485
Reference:
URL:http://www.securityfocus.com/bid/10485
Reference: XF:freebsd-jailed-table-modify(16342)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16342
Votes:
Name: CVE-2004-0127
Description:
Directory traversal vulnerability in
editconfig_gedcom.php for phpGedView 2.65.1 and earlier
allows remote attackers to read arbitrary files or
execute arbitrary PHP programs on the server via .. (dot
dot) sequences in the gedcom_config parameter.
Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040129 PHP Code Injection
Vulnerabilities in phpGedView 2.65.1 and prior
Reference:
URL:http://www.securityfocus.com/archive/1/352355
Reference: BID:9529
Reference:
URL:http://www.securityfocus.com/bid/9529
Reference: OSVDB:3768
Reference:
URL:http://www.osvdb.org/displayvuln.php?osvdb_id=3768
Reference: SECTRACK:1008892
Reference:
URL:http://www.securitytracker.com/id?1008892
Reference: SECUNIA:10753
Reference:
URL:http://secunia.com/advisories/10753/
Reference:
XF:phpgedview-editconfig-directory-traversal(15129)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15129
Votes:
ACCEPT(2) Green, Baker
NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
Green> Vendor ack'ed and provides an update;
http://prdownloads.sourceforge.net/phpgedview/phpGedView-2.65.2.zip?download
Name: CVE-2004-0130
Description:
login.php in phpGedView 2.65 and earlier allows remote
attackers to obtain sensitive information via an HTTP
request to login.php that does not contain the required
username or password parameters, which causes the
information to be leaked in an error message.
Status: Candidate
Phase: Modified (20071113)
Reference:
MISC:http://www.netvigilance.com/advisory0001
Reference:
MISC:http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html
Reference: OSVDB:6886
Reference: URL:http://www.osvdb.org/6886
Reference: SECTRACK:1008844
Reference:
URL:http://securitytracker.com/alerts/2004/Jan/1008844.html
Reference:
XF:phpgedview-loginphp-path-disclosure(15128)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15128
Votes:
ACCEPT(2) Green, Baker
NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
Green> Vendor acknowledges and supplies fix in version version 2.65.2
Name: CVE-2004-0132
Description:
Multiple PHP remote file inclusion vulnerabilities in
ezContents 2.0.2 and earlier allow remote attackers to
execute arbitrary PHP code from a remote web server, as
demonstrated using (1) the GLOBALS[rootdp] parameter to
db.php, or (2) the GLOBALS[language_home] parameter to
archivednews.php, and a malicious version of
lang_admin.php.
Status: Candidate
Phase: Modified (20060907)
Reference: BUGTRAQ:20040210 PHP Code Injection
Vulnerabilities in ezContents 2.0.2 and prior
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107651585921958&w=2
Reference:
XF:ezcontents-multiple-file-include(15135)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15135
Votes:
ACCEPT(2) Baker, Armstrong
NOOP(3) Wall, Cole, Cox
Name: CVE-2004-0133
Description:
The XFS file system code in Linux 2.4.x has an
information leak in which in-memory data is written to
the device for the XFS file system, which allows local
users to obtain sensitive information by reading the raw
device.
Status: Candidate
Phase: Assigned (20040211)
Reference: ENGARDE:ESA-20040428-004
Reference:
URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: SGI:20040405-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc
Reference: TRUSTIX:2004-0020
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference: BID:10151
Reference:
URL:http://www.securityfocus.com/bid/10151
Reference: SECUNIA:11362
Reference:
URL:http://secunia.com/advisories/11362
Reference: XF:linux-xfs-info-disclosure(15901)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15901
Votes:
Name: CVE-2004-0134
Description:
cpr (libcpr) in SGI IRIX before 6.5.25 allows local
users to gain privileges by loading a user provided
library while restarting the checkpointed process.
Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040507-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040507-01-P.asc
Reference: BID:10418
Reference:
URL:http://www.securityfocus.com/bid/10418
Reference: XF:irix-cpr-gain-privileges(16259)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16259
Votes:
Name: CVE-2004-0135
Description:
The syssgi SGI_IOPROBE system call in IRIX 6.5.20
through 6.5.24 allows local users to gain privileges by
reading and writing to kernel memory.
Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040601-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc
Reference: OSVDB:7122
Reference: URL:http://www.osvdb.org/7122
Reference: SECUNIA:11872
Reference:
URL:http://secunia.com/advisories/11872
Reference:
XF:irix-sgiioprobe-gain-privileges(16413)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16413
Votes:
Name: CVE-2004-0136
Description:
The mapelf32exec function call in IRIX 6.5.20 through
6.5.24 allows local users to cause a denial of service
(system crash) via a "corrupted binary."
Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040601-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc
Reference: OSVDB:7123
Reference: URL:http://www.osvdb.org/7123
Reference: SECUNIA:11872
Reference:
URL:http://secunia.com/advisories/11872
Reference: XF:irix-mapelf32exec-dos(16416)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16416
Reference: BID:10547
Reference:
URL:http://www.securityfocus.com/bid/10547
Votes:
Name: CVE-2004-0137
Description:
Unknown vulnerability in init for IRIX 6.5.20 through
6.5.24 allows local users to cause a denial of service
(system panic) as a result of "page invalidation
issues."
Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040601-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc
Reference: OSVDB:7124
Reference: URL:http://www.osvdb.org/7124
Reference: SECUNIA:11872
Reference:
URL:http://secunia.com/advisories/11872
Reference: XF:irix-page-dos(16417)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16417
Reference: BID:10549
Reference:
URL:http://www.securityfocus.com/bid/10549
Votes:
Name: CVE-2004-0138
Description:
The ELF loader in Linux kernel 2.4 before 2.4.25 allows
local users to cause a denial of service (crash) via a
crafted ELF file with an interpreter with an invalid
arch (architecture), which triggers a BUG() when an
invalid VMA is unmapped.
Status: Candidate
Phase: Assigned (20040211)
Reference:
CONFIRM:http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes
Reference:
CONFIRM:http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg
Reference:
CONFIRM:http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25
Reference: DEBIAN:DSA-1070
Reference:
URL:http://www.debian.org/security/2006/dsa-1070
Reference: DEBIAN:DSA-1067
Reference:
URL:http://www.debian.org/security/2006/dsa-1067
Reference: DEBIAN:DSA-1069
Reference:
URL:http://www.debian.org/security/2006/dsa-1069
Reference: DEBIAN:DSA-1082
Reference:
URL:http://www.debian.org/security/2006/dsa-1082
Reference: REDHAT:RHSA-2004:549
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-549.html
Reference: REDHAT:RHSA-2004:504
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-504.html
Reference: BID:18174
Reference:
URL:http://www.securityfocus.com/bid/18174
Reference: SECUNIA:20162
Reference:
URL:http://secunia.com/advisories/20162
Reference: SECUNIA:20163
Reference:
URL:http://secunia.com/advisories/20163
Reference: SECUNIA:20202
Reference:
URL:http://secunia.com/advisories/20202
Reference: SECUNIA:20338
Reference:
URL:http://secunia.com/advisories/20338
Reference: XF:linux-kernel-elfloader-dos(43124)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/43124
Votes:
Name: CVE-2004-0139
Description:
Unknown vulnerability in the bsd.a kernel networking for
SGI IRIX 6.5.22 through 6.5.25, and possibly earlier
versions, in which "t_unbind changes t_bind's behavior,"
has unknown impact and attack vectors.
Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040905-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040905-01-P.asc
Reference: SECUNIA:12682
Reference:
URL:http://secunia.com/advisories/12682
Reference: BID:11276
Reference:
URL:http://www.securityfocus.com/bid/11276
Reference: XF:irix-bsda-kernel(17547)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17547
Votes:
Name: CVE-2004-0140
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040211)
Votes:
Name: CVE-2004-0141
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040211)
Votes:
Name: CVE-2004-0142
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040211)
Votes:
Name: CVE-2004-0143
Description:
Multiple vulnerabilities in Nokia 6310(i) Mobile phones
allow remote attackers to cause a denial of service
(reset) via malformed Bluetooth OBject EXchange (OBEX)
messages, probably triggering buffer overflows.
Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040209 ptl-2004-01: Multiple
vulnerabilities in Nokia phones
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634788029065&w=2
Reference: VULNWATCH:20040209 ptl-2004-01:
Multiple vulnerabilities in Nokia phones
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html
Reference:
MISC:http://www.pentest.co.uk/documents/ptl-2004-01.html
Reference: BID:9603
Reference:
URL:http://www.securityfocus.com/bid/9603
Reference: XF:nokia-obex-dos(15107)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15107
Votes:
ACCEPT(3) Cole, Armstrong, Cox
NOOP(1) Wall
Voter Comments:
Armstrong> I believe that Mobile phones, PDAs etc are all valid IT devices and should be included as part of the CVE.
Name: CVE-2004-0144
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040212)
Votes:
Name: CVE-2004-0145
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040212)
Votes:
Name: CVE-2004-0146
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040212)
Votes:
Name: CVE-2004-0147
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040212)
Votes:
Name: CVE-2004-0149
Description:
Multiple buffer overflows in xboing before 2.4 allow
local users to gain privileges.
Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-451
Reference:
URL:http://www.debian.org/security/2004/dsa-451
Reference: BID:9764
Reference:
URL:http://www.securityfocus.com/bid/9764
Reference: XF:xboing-bo(15347)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15347
Votes:
Name: CVE-2004-0151
Description:
Unknown vulnerability in xitalk 1.1.11 and earlier
allows local users to execute arbitrary commands.
Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-462
Reference:
URL:http://www.debian.org/security/2004/dsa-462
Reference:
MISC:http://shellcode.org/Advisories/XITALK.txt
Reference: SECUNIA:11114
Reference:
URL:http://secunia.com/advisories/11114/
Reference: BID:9851
Reference:
URL:http://www.securityfocus.com/bid/9851
Reference: XF:xitalk-gain-privileges(15456)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15456
Votes:
Name: CVE-2004-0152
Description:
Multiple stack-based buffer overflows in (1) the
encode_mime function, (2) the encode_uuencode function,
(3) or the decode_uuencode function for emil 2.1.0 and
earlier allow remote attackers to execute arbitrary code
via e-mail messages containing attachments with
filenames.
Status: Candidate
Phase: Assigned (20040213)
Reference: BUGTRAQ:20040325 Re: [SECURITY] [DSA
468-1] New emil packages fix multiple vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108024939827236&w=2
Reference: DEBIAN:DSA-468
Reference:
URL:http://www.debian.org/security/2004/dsa-468
Reference: SUSE:SuSE-SA:2004:008
Reference: XF:emil-email-bo(15601)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15601
Votes:
Name: CVE-2004-0153
Description:
Multiple format string vulnerabilities in emil 2.1.0 and
earlier may allow remote attackers to execute arbitrary
code by triggering certain error messages.
Status: Candidate
Phase: Assigned (20040213)
Reference: BUGTRAQ:20040325 Re: [SECURITY] [DSA
468-1] New emil packages fix multiple vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108024939827236&w=2
Reference: DEBIAN:DSA-468
Reference:
URL:http://www.debian.org/security/2004/dsa-468
Reference: SUSE:SuSE-SA:2004:008
Reference: XF:emil-format-string(15602)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15602
Votes:
Name: CVE-2004-0154
Description:
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6
allows attackers to cause a denial of service (crash)
via an NFS mount of a directory from a client whose
reverse DNS lookup name is different from the forward
lookup name.
Status: Candidate
Phase: Assigned (20040213)
Reference: REDHAT:RHSA-2004:072
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-072.html
Reference: TRUSTIX:2004-0009
Reference:
URL:http://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt
Reference:
MISC:http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535
Reference: XF:nfs-utils-dns-dos(15418)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15418
Reference: BID:9813
Reference:
URL:http://www.securityfocus.com/bid/9813
Reference: OVAL:oval:org.mitre.oval:def:861
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:861
Votes:
Name: CVE-2004-0155
Description:
The KAME IKE Daemon Racoon, when authenticating a peer
during Phase 1, validates the X.509 certificate but does
not verify the RSA signature authentication, which
allows remote attackers to establish unauthorized IP
connections or conduct man-in-the-middle attacks using a
valid, trusted X.509 certificate.
Status: Candidate
Phase: Assigned (20040213)
Reference: BUGTRAQ:20040407 CAN-2004-0155: The
KAME IKE Daemon Racoon does not verify RSA Signatures
during Phase 1, allows man-in-the-middle attacks and
unauthorized connections
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108136746911000&w=2
Reference: GENTOO:GLSA-200406-17
Reference:
URL:http://www.gentoo.org/security/en/glsa/glsa-200406-17.xml
Reference: MANDRAKE:MDKSA-2004:027
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:027
Reference: MANDRAKE:MDKSA-2004:069
Reference:
URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069
Reference: APPLE:APPLE-SA-2004-05-03
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108369640424244&w=2
Reference: REDHAT:RHSA-2004:165
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-165.html
Reference: SCO:SCOSA-2005.10
Reference:
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
Reference: CERT-VN:VU#552398
Reference:
URL:http://www.kb.cert.org/vuls/id/552398
Reference: OVAL:oval:org.mitre.oval:def:945
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:945
Reference: SECUNIA:11328
Reference:
URL:http://secunia.com/advisories/11328
Votes:
Name: CVE-2004-0156
Description:
Format string vulnerabilities in the (1) die or (2)
log_event functions for ssmtp before 2.50.6 allow remote
mail relays to cause a denial of service and possibly
execute arbitrary code.
Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-485
Reference:
URL:http://www.debian.org/security/2004/dsa-485
Reference: GENTOO:GLSA-200404-18
Reference:
URL:http://security.gentoo.org/glsa/glsa-200404-18.xml
Reference: BUGTRAQ:20040507 [OpenPKG-SA-2004.020]
OpenPKG Security Advisory (ssmtp)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403772130855&w=2
Reference: BID:10150
Reference:
URL:http://www.securityfocus.com/bid/10150
Reference: OSVDB:5360
Reference: URL:http://www.osvdb.org/5360
Reference: OSVDB:5361
Reference: URL:http://www.osvdb.org/5361
Reference: SECTRACK:1009788
Reference:
URL:http://securitytracker.com/id?1009788
Reference: SECUNIA:11378
Reference:
URL:http://secunia.com/advisories/11378
Reference: SECUNIA:11384
Reference:
URL:http://secunia.com/advisories/11384
Reference: SECUNIA:11485
Reference:
URL:http://secunia.com/advisories/11485
Reference: SECUNIA:11571
Reference:
URL:http://secunia.com/advisories/11571
Reference:
XF:ssmtp-die-logevent-format-string(15872)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15872
Votes:
Name: CVE-2004-0157
Description:
x11.c in xonix 1.4 and earlier uses the current working
directory to find and execute the rmail program, which
allows local users to execute arbitrary code by
modifying the path to point to a malicious rmail
program.
Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-484
Reference:
URL:http://www.debian.org/security/2004/dsa-484
Reference:
MISC:http://shellcode.org/Advisories/XONIX.txt
Reference: BID:10149
Reference:
URL:http://www.securityfocus.com/bid/10149
Reference: OSVDB:5358
Reference: URL:http://www.osvdb.org/5358
Reference: SECTRACK:1009789
Reference:
URL:http://securitytracker.com/id?1009789
Reference: SECUNIA:11382
Reference:
URL:http://secunia.com/advisories/11382
Reference: XF:xonix-privilege-dropping(15873)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15873
Votes:
Name: CVE-2004-0158
Description:
Buffer overflow in lbreakout2 allows local users to gain
'games' group privileges via a large HOME environment
variable to (1) editor.c, (2) theme.c, (3) manager.c,
(4) config.c, (5) game.c, (6) levels.c, or (7) main.c.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040222 lbreakout2 <
2.4beta-2 local exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107755821705356&w=2
Reference: DEBIAN:DSA-445
Reference:
URL:http://www.debian.org/security/2004/dsa-445
Reference:
CONFIRM:http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz
Reference: BID:9712
Reference:
URL:http://www.securityfocus.com/bid/9712
Reference: XF:breakout2-home-bo(15229)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15229
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0161
Description:
Multiple content security gateway and antivirus products
allow remote attackers to bypass content restrictions
via MIME messages that use RFC2231 encoding, which may
be interpreted differently by mail clients.
Status: Candidate
Phase: Assigned (20040218)
Reference: BUGTRAQ:20040914 Corsaire Security
Advisory - Multiple vendor MIME RFC2231 encoding issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109524928232568&w=2
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference: XF:mime-tools-parameter-encoding(9274)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/9274
Votes:
Name: CVE-2004-0162
Description:
Multiple content security gateway and antivirus products
allow remote attackers to bypass content restrictions
via MIME encapsulation that uses RFC822 comment fields,
which may be interpreted as other fields by mail
clients.
Status: Candidate
Phase: Assigned (20040218)
Reference: BUGTRAQ:20040914 Corsaire Security
Advisory - Multiple vendor MIME RFC822 comment issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109517563513776&w=2
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference: XF:mime-rfc822-filtering-bypass(17332)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17332
Votes:
Name: CVE-2004-0163
Description:
Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does
not change the key used to encrypt data, which allows
remote attackers to cause a denial of service (resource
exhaustion) by capturing a session and repeatedly
replaying the session.
Status: Candidate
Phase: Assigned (20040218)
Reference: BUGTRAQ:20040810 Corsaire Security
Advisory - Sygate Secure Enterprise replay issue
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109215685731675&w=2
Reference:
MISC:http://www.corsaire.com/advisories/c031120-002.txt
Reference: XF:sse-replay-dos(16945)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16945
Votes:
Name: CVE-2004-0164
Description:
KAME IKE daemon (racoon) does not properly handle hash
values, which allows remote attackers to delete
certificates via (1) a certain delete message that is
not properly handled in isakmp.c or isakmp_inf.c, or (2)
a certain INITIAL-CONTACT message that is not properly
handled in isakmp_inf.c.
Status: Candidate
Phase: Modified (20061101)
Reference: BUGTRAQ:20040113 unauthorized deletion
of IPsec (and ISAKMP) SAs in racoon
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107403331309838&w=2
Reference: BUGTRAQ:20040114 Re: unauthorized
deletion of IPsec (and ISAKMP) SAs in racoon
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411758202662&w=2
Reference: APPLE:APPLE-SA-2004-02-23
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: NETBSD:NetBSD-SA2004-001
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc
Reference:
XF:openbsd-isakmp-initialcontact-delete-sa(14118)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14118
Reference:
XF:openbsd-isakmp-invalidspi-delete-sa(14117)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14117
Reference: BID:9416
Reference:
URL:http://www.securityfocus.com/bid/9416
Reference: BID:9417
Reference:
URL:http://www.securityfocus.com/bid/9417
Reference: OVAL:oval:org.mitre.oval:def:947
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947
Votes:
ACCEPT(4) Baker, Cole, Armstrong, Cox
NOOP(2) Christey, Wall
Voter Comments:
CHANGE> [Cox changed vote from NOOP to ACCEPT]
Christey> REDHAT:RHSA-2004:165
URL:http://www.redhat.com/support/errata/RHSA-2004-165.html
Christey> SCO:SCOSA-2005.10
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
Name: CVE-2004-0166
Description:
Unknown vulnerability in Safari web browser for Mac OS X
10.2.8 related to "the display of URLs in the status
bar."
Status: Candidate
Phase: Modified (20050510)
Reference: APPLE:APPLE-SA-2004-02-23
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: CERT-VN:VU#194238
Reference:
URL:http://www.kb.cert.org/vuls/id/194238
Reference: SECUNIA:10959
Reference:
URL:http://secunia.com/advisories/10959
Reference: XF:macosx-safari-unknown(14993)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14993
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0168
Description:
Unknown vulnerability in CoreFoundation for Mac OS X
10.3.2, related to "notification logging."
Status: Candidate
Phase: Modified (20050808)
Reference: APPLE:APPLE-SA-2004-02-23
Reference:
URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: SECUNIA:10959
Reference:
URL:http://secunia.com/advisories/10959/
Reference: XF:macos-corefoundation-unknown(15299)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15299
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0170
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040219)
Votes:
Name: CVE-2004-0172
Description:
Heap-based buffer overflow in the search_for_command
function of ltrace 0.3.10, if it is installed setuid,
could allow local users to execute arbitrary code via a
long filename. NOTE: It is unclear whether there are any
packages that install ltrace as a setuid program, so
this candidate might be REJECTed.
Status: Candidate
Phase: Assigned (20040220)
Reference: FULLDISC:20031008 ltrace bug
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html
Reference: FULLDISC:20031008 ltrace bug
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html
Reference: BID:8790
Reference:
URL:http://www.securityfocus.com/bid/8790
Reference: SECTRACK:1007896
Reference:
URL:http://securitytracker.com/id?1007896
Reference: XF:ltrace-searchforcommand-bo(13389)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/13389
Votes:
Name: CVE-2004-0174
Description:
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49,
when using multiple listening sockets on certain
platforms, allows remote attackers to cause a denial of
service (blocked new connections) via a "short-lived
connection on a rarely-accessed listening socket."
Status: Candidate
Phase: Assigned (20040225)
Reference: BUGTRAQ:20040319 [ANNOUNCE] Apache
HTTP Server 2.0.49 Released (fwd)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107973894328806&w=2
Reference:
CONFIRM:http://www.apache.org/dist/httpd/CHANGES_1.3
Reference: SUNALERT:101555
Reference:
URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1
Reference: TRUSTIX:2004-0017
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108066914830552&w=2
Reference: APPLE:APPLE-SA-2004-05-03
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108369640424244&w=2
Reference: BUGTRAQ:20040512 [OpenPKG-SA-2004.021]
OpenPKG Security Advisory (apache)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108437852004207&w=2
Reference: SLACKWARE:SSA:2004-133
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.529643
Reference: SUNALERT:57628
Reference:
URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1
Reference: TRUSTIX:2004-0027
Reference:
URL:http://www.trustix.org/errata/2004/0027
Reference: GENTOO:GLSA-200405-22
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-22.xml
Reference: HP:SSRT4717
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108731648532365&w=2
Reference: MANDRAKE:MDKSA-2004:046
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:046
Reference: REDHAT:RHSA-2004:405
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-405.html
Reference: CERT-VN:VU#132110
Reference:
URL:http://www.kb.cert.org/vuls/id/132110
Reference: OVAL:oval:org.mitre.oval:def:100110
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100110
Reference: SECUNIA:11170
Reference:
URL:http://secunia.com/advisories/11170
Reference: BID:9921
Reference:
URL:http://www.securityfocus.com/bid/9921
Reference: SECTRACK:1009495
Reference:
URL:http://www.securitytracker.com/alerts/2004/Mar/1009495.html
Reference: OVAL:oval:org.mitre.oval:def:1982
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1982
Reference: XF:apache-socket-starvation-dos(15540)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15540
Votes:
Name: CVE-2004-0175
Description:
Directory traversal vulnerability in scp for OpenSSH
before 3.4p1 allows remote malicious servers to
overwrite arbitrary files. NOTE: this may be a
rediscovery of CVE-2000-0992.
Status: Candidate
Phase: Assigned (20040225)
Reference:
CONFIRM:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147
Reference:
CONFIRM:http://www.juniper.net/support/security/alerts/adv59739.txt
Reference: CONECTIVA:CLSA-2004:831
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000831
Reference: MANDRIVA:MDKSA-2005:100
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:100
Reference: MANDRIVA:MDVSA-2008:191
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:191
Reference: REDHAT:RHSA-2005:106
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-106.html
Reference: REDHAT:RHSA-2005:074
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-074.html
Reference: REDHAT:RHSA-2005:165
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-165.html
Reference: REDHAT:RHSA-2005:481
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-481.html
Reference: REDHAT:RHSA-2005:495
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-495.html
Reference: REDHAT:RHSA-2005:562
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-562.html
Reference: REDHAT:RHSA-2005:567
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-567.html
Reference: SCO:SCOSA-2006.11
Reference:
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt
Reference: SUSE:SuSE-SA:2004:009
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_09_kernel.html
Reference: CIAC:O-212
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-212.shtml
Reference: BID:9986
Reference:
URL:http://www.securityfocus.com/bid/9986
Reference: OSVDB:9550
Reference: URL:http://www.osvdb.org/9550
Reference: SECUNIA:19243
Reference:
URL:http://secunia.com/advisories/19243
Reference: SECUNIA:17135
Reference:
URL:http://secunia.com/advisories/17135
Reference: XF:openssh-scp-file-overwrite(16323)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16323
Votes:
Name: CVE-2004-0176
Description:
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2
allow remote attackers to cause a denial of service and
possibly execute arbitrary code via the (1) NetFlow, (2)
IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP,
or (8) TCAP dissectors.
Status: Candidate
Phase: Assigned (20040225)
Reference: BUGTRAQ:20040323 Advisory 03/2004:
Multiple (13) Ethereal remote overflows
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108007072215742&w=2
Reference:
MISC:http://security.e-matters.de/advisories/032004.html
Reference:
CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00013.html
Reference: DEBIAN:DSA-511
Reference:
URL:http://www.debian.org/security/2004/dsa-511
Reference: BUGTRAQ:20040329 LNSA-#2004-0007:
Multiple security problems in Ethereal
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058005324316&w=2
Reference: GENTOO:GLSA-200403-07
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-07.xml
Reference: REDHAT:RHSA-2004:136
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-136.html
Reference: REDHAT:RHSA-2004:137
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-137.html
Reference: CONECTIVA:CLA-2004:835
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
Reference: MANDRAKE:MDKSA-2004:024
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
Reference: BUGTRAQ:20040416 [OpenPKG-SA-2004.015]
OpenPKG Security Advisory (ethereal)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213710306260&w=2
Reference: CERT-VN:VU#119876
Reference:
URL:http://www.kb.cert.org/vuls/id/119876
Reference: CERT-VN:VU#125156
Reference:
URL:http://www.kb.cert.org/vuls/id/125156
Reference: CERT-VN:VU#433596
Reference:
URL:http://www.kb.cert.org/vuls/id/433596
Reference: CERT-VN:VU#591820
Reference:
URL:http://www.kb.cert.org/vuls/id/591820
Reference: CERT-VN:VU#644886
Reference:
URL:http://www.kb.cert.org/vuls/id/644886
Reference: CERT-VN:VU#659140
Reference:
URL:http://www.kb.cert.org/vuls/id/659140
Reference: CERT-VN:VU#740188
Reference:
URL:http://www.kb.cert.org/vuls/id/740188
Reference: CERT-VN:VU#864884
Reference:
URL:http://www.kb.cert.org/vuls/id/864884
Reference: CERT-VN:VU#931588
Reference:
URL:http://www.kb.cert.org/vuls/id/931588
Reference: OSVDB:6893
Reference: URL:http://www.osvdb.org/6893
Reference: OVAL:oval:org.mitre.oval:def:878
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:878
Reference: OVAL:oval:org.mitre.oval:def:887
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:887
Reference: SECUNIA:11185
Reference:
URL:http://secunia.com/advisories/11185
Reference:
XF:ethereal-multiple-dissectors-bo(15569)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15569
Votes:
Name: CVE-2004-0177
Description:
The ext3 code in Linux 2.4.x before 2.4.26 does not
properly initialize journal descriptor blocks, which
causes an information leak in which in-memory data is
written to the device for the ext3 file system, which
allows privileged users to obtain portions of kernel
memory by reading the raw device.
Status: Candidate
Phase: Assigned (20040225)
Reference: CONECTIVA:CLA-2004:846
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-479
Reference:
URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference:
URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference:
URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference:
URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference:
URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference:
URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference:
URL:http://www.debian.org/security/2004/dsa-495
Reference: ENGARDE:ESA-20040428-004
Reference:
URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: FEDORA:FLSA:2336
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=2336
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:166
Reference:
URL:http://rhn.redhat.com/errata/RHSA-2004-166.html
Reference: REDHAT:RHSA-2005:293
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-293.html
Reference: REDHAT:RHSA-2004:504
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-504.html
Reference: REDHAT:RHSA-2004:505
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-505.html
Reference: TRUSTIX:2004-0020
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference:
MISC:http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ
Reference: CIAC:O-121
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-126
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-126.shtml
Reference: CIAC:O-127
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: BID:10152
Reference:
URL:http://www.securityfocus.com/bid/10152
Reference: XF:linux-ext3-info-disclosure(15867)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15867
Votes:
Name: CVE-2004-0178
Description:
The OSS code for the Sound Blaster (sb16) driver in
Linux 2.4.x before 2.4.26, when operating in 16 bit
mode, does not properly handle certain sample sizes,
which allows local users to cause a denial of service
(crash) via a sample with an odd number of bytes.
Status: Candidate
Phase: Assigned (20040225)
Reference: CONECTIVA:CLA-2004:846
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-479
Reference:
URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference:
URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference:
URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference:
URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference:
URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference:
URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference:
URL:http://www.debian.org/security/2004/dsa-495
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:413
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-413.html
Reference: REDHAT:RHSA-2004:437
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-437.html
Reference: SGI:20040804-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc
Reference:
MISC:http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA
Reference: CIAC:O-121
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-127
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: CIAC:O-193
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-193.shtml
Reference: BID:9985
Reference:
URL:http://www.securityfocus.com/bid/9985
Reference: XF:linux-sound-blaster-dos(15868)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15868
Votes:
Name: CVE-2004-0179
Description:
Multiple format string vulnerabilities in (1) neon
0.24.4 and earlier, and other products that use neon
including (2) Cadaver, (3) Subversion, and (4)
OpenOffice, allow remote malicious WebDAV servers to
execute arbitrary code.
Status: Candidate
Phase: Assigned (20040225)
Reference: BUGTRAQ:20040416 void.at - neon format
string bugs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108214147022626&w=2
Reference: DEBIAN:DSA-487
Reference:
URL:http://www.debian.org/security/2004/dsa-487
Reference: FEDORA:FEDORA-2004-1552
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1552
Reference: REDHAT:RHSA-2004:157
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-157.html
Reference: REDHAT:RHSA-2004:158
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-158.html
Reference: REDHAT:RHSA-2004:159
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-159.html
Reference: REDHAT:RHSA-2004:160
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-160.html
Reference: SGI:20040404-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
Reference: SUSE:SuSE-SA:2004:008
Reference:
URL:http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html
Reference: SUSE:SuSE-SA:2004:009
Reference:
URL:http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html
Reference: BUGTRAQ:20040416 [OpenPKG-SA-2004.016]
OpenPKG Security Advisory (neon)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213873203477&w=2
Reference: GENTOO:GLSA-200405-01
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-01.xml
Reference: GENTOO:GLSA-200405-04
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-04.xml
Reference: MANDRAKE:MDKSA-2004:032
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:032
Reference: BID:10136
Reference:
URL:http://www.securityfocus.com/bid/10136
Reference: OSVDB:5365
Reference: URL:http://www.osvdb.org/5365
Reference: OVAL:oval:org.mitre.oval:def:1065
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1065
Reference: SECUNIA:11363
Reference:
URL:http://secunia.com/advisories/11363
Votes:
Name: CVE-2004-0180
Description:
The client for CVS before 1.11 allows a remote malicious
CVS server to create arbitrary files using certain RCS
diff files that use absolute pathnames during checkouts
or updates, a different vulnerability than
CVE-2004-0405.
Status: Candidate
Phase: Assigned (20040225)
Reference: DEBIAN:DSA-486
Reference:
URL:http://www.debian.org/security/2004/dsa-486
Reference: FEDORA:FEDORA-2004-1620
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108636445031613&w=2
Reference: FREEBSD:FreeBSD-SA-04:07
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc
Reference: GENTOO:GLSA-200404-13
Reference:
URL:http://security.gentoo.org/glsa/glsa-200404-13.xml
Reference: MANDRAKE:MDKSA-2004:028
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:028
Reference: REDHAT:RHSA-2004:153
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-153.html
Reference: REDHAT:RHSA-2004:154
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-154.html
Reference: SGI:20040404-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
Reference: SLACKWARE:SSA:2004-108-02
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.400181
Reference: SUSE:SuSE-SA:2004:008
Reference:
CONFIRM:ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch
Reference: OVAL:oval:org.mitre.oval:def:1042
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1042
Reference: SECUNIA:11368
Reference:
URL:http://secunia.com/advisories/11368
Reference: SECUNIA:11371
Reference:
URL:http://secunia.com/advisories/11371
Reference: SECUNIA:11374
Reference:
URL:http://secunia.com/advisories/11374
Reference: SECUNIA:11375
Reference:
URL:http://secunia.com/advisories/11375
Reference: SECUNIA:11377
Reference:
URL:http://secunia.com/advisories/11377
Reference: SECUNIA:11380
Reference:
URL:http://secunia.com/advisories/11380
Reference: SECUNIA:11391
Reference:
URL:http://secunia.com/advisories/11391
Reference: SECUNIA:11400
Reference:
URL:http://secunia.com/advisories/11400
Reference: SECUNIA:11405
Reference:
URL:http://secunia.com/advisories/11405
Reference: SECUNIA:11548
Reference:
URL:http://secunia.com/advisories/11548
Reference: XF:cvs-rcs-create-files(15864)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15864
Votes:
Name: CVE-2004-0181
Description:
The JFS file system code in Linux 2.4.x has an
information leak in which in-memory data is written to
the device for the JFS file system, which allows local
users to obtain sensitive information by reading the raw
device.
Status: Candidate
Phase: Assigned (20040225)
Reference: ENGARDE:ESA-20040428-004
Reference:
URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2005:663
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2005-663.html
Reference: REDHAT:RHSA-2004:504
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-504.html
Reference: TRUSTIX:2004-0020
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference: TURBO:TLSA-2004-14
Reference:
URL:http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
Reference: BID:10143
Reference:
URL:http://www.securityfocus.com/bid/10143
Reference: FRSIRT:ADV-2005-1878
Reference:
URL:http://www.frsirt.com/english/advisories/2005/1878
Reference: SECUNIA:17002
Reference:
URL:http://secunia.com/advisories/17002
Reference: XF:linux-jfs-info-disclosure(15902)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15902
Votes:
Name: CVE-2004-0182
Description:
Mailman before 2.0.13 allows remote attackers to cause a
denial of service (crash) via an email message with an
empty subject field.
Status: Candidate
Phase: Assigned (20040225)
Reference: REDHAT:RHSA-2004:156
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-156.html
Reference: SGI:20040404-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
Votes:
Name: CVE-2004-0183
Description:
TCPDUMP 3.8.1 and earlier allows remote attackers to
cause a denial of service (crash) via ISAKMP packets
containing a Delete payload with a large number of
SPI's, which causes an out-of-bounds read, as
demonstrated by the Striker ISAKMP Protocol Test Suite.
Status: Candidate
Phase: Assigned (20040302)
Reference: BUGTRAQ:20040330 R7-0017: TCPDUMP
ISAKMP payload handling denial-of-service
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108067265931525&w=2
Reference:
MISC:http://www.rapid7.com/advisories/R7-0017.html
Reference:
CONFIRM:http://www.tcpdump.org/tcpdump-changes.txt
Reference: DEBIAN:DSA-478
Reference:
URL:http://www.debian.org/security/2004/dsa-478
Reference: FEDORA:FEDORA-2004-1468
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1468
Reference: REDHAT:RHSA-2004:219
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-219.html
Reference: TRUSTIX:2004-0015
Reference:
URL:http://www.trustix.org/errata/2004/0015
Reference: CERT-VN:VU#240790
Reference:
URL:http://www.kb.cert.org/vuls/id/240790
Reference: BID:10003
Reference:
URL:http://www.securityfocus.com/bid/10003
Reference: OVAL:oval:org.mitre.oval:def:972
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972
Reference: SECTRACK:1009593
Reference:
URL:http://securitytracker.com/id?1009593
Reference: SECUNIA:11258
Reference:
URL:http://secunia.com/advisories/11258
Reference: SECUNIA:11320
Reference:
URL:http://secunia.com/advisories/11320
Reference: XF:tcpdump-isakmp-delete-bo(15680)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15680
Votes:
Name: CVE-2004-0184
Description:
Integer underflow in the isakmp_id_print for TCPDUMP
3.8.1 and earlier allows remote attackers to cause a
denial of service (crash) via an ISAKMP packet with an
Identification payload with a length that becomes less
than 8 during byte order conversion, which causes an
out-of-bounds read, as demonstrated by the Striker
ISAKMP Protocol Test Suite.
Status: Candidate
Phase: Assigned (20040302)
Reference: BUGTRAQ:20040330 R7-0017: TCPDUMP
ISAKMP payload handling denial-of-service
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108067265931525&w=2
Reference:
MISC:http://www.rapid7.com/advisories/R7-0017.html
Reference:
CONFIRM:http://www.tcpdump.org/tcpdump-changes.txt
Reference: DEBIAN:DSA-478
Reference:
URL:http://www.debian.org/security/2004/dsa-478
Reference: FEDORA:FEDORA-2004-1468
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1468
Reference: REDHAT:RHSA-2004:219
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-219.html
Reference: TRUSTIX:2004-0015
Reference:
URL:http://www.trustix.org/errata/2004/0015
Reference: CERT-VN:VU#492558
Reference:
URL:http://www.kb.cert.org/vuls/id/492558
Reference: BID:10004
Reference:
URL:http://www.securityfocus.com/bid/10004
Reference: OVAL:oval:org.mitre.oval:def:976
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:976
Reference: SECTRACK:1009593
Reference:
URL:http://securitytracker.com/id?1009593
Reference: SECUNIA:11258
Reference:
URL:http://secunia.com/advisories/11258
Reference:
XF:tcpdump-isakmp-integer-underflow(15679)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15679
Votes:
Name: CVE-2004-0187
Description:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.
ConsultIDs: CVE-2004-0185. Reason: This candidate is a
reservation duplicate of CVE-2004-0185. Notes: All CVE
users should reference CVE-2004-0185 instead of this
candidate. All references and descriptions in this
candidate have been removed to prevent accidental usage.
Status: Candidate
Phase: Assigned (20040302)
Votes:
Name: CVE-2004-0192
Description:
Cross-site scripting (XSS) vulnerability in the
Management Service for Symantec Gateway Security 2.0
allows remote attackers to steal cookies and hijack a
management session via a /sgmi URL that contains
malicious script, which is not quoted in the resulting
error page.
Status: Candidate
Phase: Modified (20040813)
Reference: BUGTRAQ:20040227 Symantec Gateway
Security Management Service Cross Site Scripting
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107790684732458&w=2
Reference: BID:9755
Reference:
URL:http://www.securityfocus.com/bid/9755
Reference: XF:symantecgateway-error-xss(15330)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15330
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0195
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040309)
Votes:
Name: CVE-2004-0196
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040309)
Votes:
Name: CVE-2004-0197
Description:
Buffer overflow in Microsoft Jet Database Engine 4.0
allows remote attackers to execute arbitrary code via a
specially-crafted database query.
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-014
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-014.asp
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#740716
Reference:
URL:http://www.kb.cert.org/vuls/id/740716
Reference: BID:10112
Reference:
URL:http://www.securityfocus.com/bid/10112
Reference: OVAL:oval:org.mitre.oval:def:968
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:968
Reference: XF:msjet-query-execute-code(15703)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15703
Votes:
Name: CVE-2004-0198
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040311)
Votes:
Name: CVE-2004-0199
Description:
Help and Support Center in Microsoft Windows XP and
Windows Server 2003 SP1 does not properly validate HCP
URLs, which allows remote attackers to execute arbitrary
code, as demonstrated using certain hcp:// URLs that
access the DVD Upgrade capability (dvdupgrd.htm).
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040512 MS04-015 - Windows
Help Center - Dvdupgrade
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108437759930820&w=2
Reference: FULLDISC:20040512 MS04-015 - Windows
Help Center - Dvdupgrade
Reference:
URL:http://marc.theaimsgroup.com/?l=full-disclosure&m=108430407801825&w=2
Reference:
MISC:http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt
Reference: MS:MS04-015
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx
Reference: CERT-VN:VU#484814
Reference:
URL:http://www.kb.cert.org/vuls/id/484814
Reference: XF:win-hcp-code-execution(16095)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16095
Reference: BID:10321
Reference:
URL:http://www.securityfocus.com/bid/10321
Reference: OVAL:oval:org.mitre.oval:def:1008
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1008
Reference: OVAL:oval:org.mitre.oval:def:1032
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1032
Votes:
Name: CVE-2004-0200
Description:
Buffer overflow in the JPEG (JPG) parsing engine in the
Microsoft Graphic Device Interface Plus (GDI+)
component, GDIPlus.dll, allows remote attackers to
execute arbitrary code via a JPEG image with a small
JPEG COM field length that is normalized to a large
integer length before a memory copy operation.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040914 Microsoft GDIPlus.DLL
JPEG Parsing Engine Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109524346729948&w=2
Reference: MS:MS04-028
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-028.asp
Reference: CERT:TA04-260A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-260A.html
Reference: CERT-VN:VU#297462
Reference:
URL:http://www.kb.cert.org/vuls/id/297462
Reference: OVAL:oval:org.mitre.oval:def:1105
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1105
Reference: OVAL:oval:org.mitre.oval:def:1721
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1721
Reference: OVAL:oval:org.mitre.oval:def:2706
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2706
Reference: OVAL:oval:org.mitre.oval:def:3038
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3038
Reference: OVAL:oval:org.mitre.oval:def:3082
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3082
Reference: OVAL:oval:org.mitre.oval:def:3320
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3320
Reference: OVAL:oval:org.mitre.oval:def:3810
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3810
Reference: OVAL:oval:org.mitre.oval:def:3881
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3881
Reference: OVAL:oval:org.mitre.oval:def:4003
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4003
Reference: OVAL:oval:org.mitre.oval:def:4216
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4216
Reference: OVAL:oval:org.mitre.oval:def:4307
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4307
Reference: XF:win-jpeg-bo(16304)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16304
Votes:
Name: CVE-2004-0201
Description:
Heap-based buffer overflow in the HtmlHelp program
(hh.exe) in HTML Help for Microsoft Windows 98, Me, NT
4.0, 2000, XP, and Server 2003 allows remote attackers
to execute arbitrary commands via a .CHM file with a
large length field, a different vulnerability than
CVE-2003-1041.
Status: Candidate
Phase: Assigned (20040311)
Reference: FULLDISC:20040714 HtmlHelp - .CHM File
Heap Overflow
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
Reference: MS:MS04-023
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx
Reference: CERT:TA04-196A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#920060
Reference:
URL:http://www.kb.cert.org/vuls/id/920060
Reference: XF:win-htmlhelp-execute-code(16586)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16586
Reference: OVAL:oval:org.mitre.oval:def:1503
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1503
Reference: OVAL:oval:org.mitre.oval:def:1530
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1530
Reference: OVAL:oval:org.mitre.oval:def:2155
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2155
Reference: OVAL:oval:org.mitre.oval:def:3179
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3179
Votes:
Name: CVE-2004-0202
Description:
IDirectPlay4 Application Programming Interface (API) of
Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows
Server 2003 and earlier allows remote attackers to cause
a denial of service (application crash) via a malformed
packet.
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-016
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-016.asp
Reference: BID:10487
Reference:
URL:http://www.securityfocus.com/bid/10487
Reference: OSVDB:6742
Reference: URL:http://www.osvdb.org/6742
Reference: OVAL:oval:org.mitre.oval:def:1027
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1027
Reference: OVAL:oval:org.mitre.oval:def:2190
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2190
Reference: OVAL:oval:org.mitre.oval:def:2413
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2413
Reference: OVAL:oval:org.mitre.oval:def:2516
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2516
Reference: OVAL:oval:org.mitre.oval:def:2705
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2705
Reference: SECUNIA:11802
Reference:
URL:http://secunia.com/advisories/11802
Reference: XF:ms-directx-directplay-dos(16306)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16306
Votes:
Name: CVE-2004-0203
Description:
Cross-site scripting (XSS) vulnerability in Outlook Web
Access for Exchange Server 5.5 Service Pack 4 allows
remote attackers to insert arbitrary script and spoof
content in HTML email or web caches via an HTML redirect
query.
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-026
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx
Reference: CERT-VN:VU#948750
Reference:
URL:http://www.kb.cert.org/vuls/id/948750
Reference: OVAL:oval:org.mitre.oval:def:2016
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2016
Reference: XF:exchange-owa-execute-code(16583)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16583
Votes:
Name: CVE-2004-0204
Description:
Directory traversal vulnerability in the web viewers for
Business Objects Crystal Reports 9 and 10, and Crystal
Enterprise 9 or 10, as used in Visual Studio .NET 2003
and Outlook 2003 with Business Contact Manager,
Microsoft Business Solutions CRM 1.2, and other
products, allows remote attackers to read and delete
arbitrary files via ".." sequences in the dynamicimag
argument to crystalimagehandler.aspx.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040502 Crystal Reports
Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108360413811017&w=2
Reference: BUGTRAQ:20040608 Vulnerability:
Arbitrary File Access & DoS in Crystal Reports
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108671836127360&w=2
Reference:
CONFIRM:http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp
Reference: MS:MS04-017
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-017.asp
Reference: BID:10260
Reference:
URL:http://www.securityfocus.com/bid/10260
Reference: OSVDB:6748
Reference: URL:http://www.osvdb.org/6748
Reference: OVAL:oval:org.mitre.oval:def:1157
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1157
Reference: SECUNIA:11800
Reference:
URL:http://secunia.com/advisories/11800
Reference: XF:crystalreports-file-deletion(16044)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16044
Votes:
Name: CVE-2004-0205
Description:
Buffer overflow in Microsoft Internet Information Server
(IIS) 4.0 allows local users to execute arbitrary code
via the redirect function.
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-021
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-021.asp
Reference: CERT:TA04-196A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#717748
Reference:
URL:http://www.kb.cert.org/vuls/id/717748
Reference: CIAC:O-179
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-179.shtml
Reference: BID:10706
Reference:
URL:http://www.securityfocus.com/bid/10706
Reference: OSVDB:7799
Reference: URL:http://www.osvdb.org/7799
Reference: OVAL:oval:org.mitre.oval:def:2204
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2204
Reference: SECUNIA:12061
Reference:
URL:http://secunia.com/advisories/12061
Reference: XF:iis-redirect-bo(16578)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16578
Votes:
Name: CVE-2004-0206
Description:
Network Dynamic Data Exchange (NetDDE) services for
Microsoft Windows 98, Windows NT 4.0, Windows 2000,
Windows XP, and Windows Server 2003 allows attackers to
remotely execute arbitrary code or locally gain
privileges via a malicious message or application that
involves an "unchecked buffer," possibly a buffer
overflow.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041013 Microsoft Windows
NetDDE Service Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109786703930674&w=2
Reference: MS:MS04-031
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-031.asp
Reference: CERT-VN:VU#640488
Reference:
URL:http://www.kb.cert.org/vuls/id/640488
Reference: BID:11372
Reference:
URL:http://www.securityfocus.com/bid/11372
Reference: OVAL:oval:org.mitre.oval:def:1852
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1852
Reference: OVAL:oval:org.mitre.oval:def:2394
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2394
Reference: OVAL:oval:org.mitre.oval:def:3120
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3120
Reference: OVAL:oval:org.mitre.oval:def:3242
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3242
Reference: OVAL:oval:org.mitre.oval:def:4592
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4592
Reference: OVAL:oval:org.mitre.oval:def:5074
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5074
Reference: OVAL:oval:org.mitre.oval:def:6788
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6788
Reference: XF:win-netdde-bo(16556)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16556
Reference: XF:win-ms04031-patch(17657)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17657
Reference: SECUNIA:12803
Reference:
URL:http://secunia.com/advisories/12803/
Votes:
Name: CVE-2004-0207
Description:
"Shatter" style vulnerability in the Window Management
application programming interface (API) for Microsoft
Windows 98, Windows NT 4.0, Windows 2000, Windows XP,
and Windows Server 2003 allows local users to gain
privileges by using certain API functions to change
properties of privileged programs using the
SetWindowLong and SetWIndowLongPtr API functions.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041013 SetWindowLong Shatter
Attacks
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109777417922695&w=2
Reference: MS:MS04-032
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference:
XF:win-mngmt-api-gain-privileges(16579)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16579
Reference: XF:win-ms04032-patch(17658)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: CERT-VN:VU#218526
Reference:
URL:http://www.kb.cert.org/vuls/id/218526
Votes:
Name: CVE-2004-0208
Description:
The Virtual DOS Machine (VDM) subsystem of Microsoft
Windows NT 4.0, Windows 2000, Windows XP, and Windows
Server 2003 allows local users to access kernel memory
and gain privileges via a malicious program that
modified some system structures in a way that is not
properly validated by privileged operating system
functions.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041013 EEYE: Windows VDM #UD
Local Privilege Escalation
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109772135404427&w=2
Reference: MS:MS04-032
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference: OVAL:oval:org.mitre.oval:def:1751
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751
Reference: OVAL:oval:org.mitre.oval:def:3161
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161
Reference: OVAL:oval:org.mitre.oval:def:3953
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953
Reference: OVAL:oval:org.mitre.oval:def:4316
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316
Reference: OVAL:oval:org.mitre.oval:def:4762
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762
Reference: XF:win-ms04032-patch(17658)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: XF:win-vdm-gain-privilege(16580)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16580
Reference: CERT-VN:VU#910998
Reference:
URL:http://www.kb.cert.org/vuls/id/910998
Votes:
Name: CVE-2004-0209
Description:
Unknown vulnerability in the Graphics Rendering Engine
processes of Microsoft Windows 2000, Windows XP, and
Windows Server 2003 allows remote attackers to execute
arbitrary code via (1) Windows Metafile (WMF) or (2)
Enhanced Metafile (EMF) image formats that involve "an
unchecked buffer."
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-032
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference: BUGTRAQ:20041019 [EXPL] (MS04-032)
Microsoft Windows XP Metafile (.emf) Heap Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109829067325779&w=2
Reference: BID:11375
Reference:
URL:http://www.securityfocus.com/bid/11375
Reference: OVAL:oval:org.mitre.oval:def:1872
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1872
Reference: OVAL:oval:org.mitre.oval:def:2114
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2114
Reference: OVAL:oval:org.mitre.oval:def:2428
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2428
Reference: XF:win-emf-bo(16581)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16581
Reference: XF:win-ms04032-patch(17658)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: CERT-VN:VU#806278
Reference:
URL:http://www.kb.cert.org/vuls/id/806278
Votes:
Name: CVE-2004-0210
Description:
The POSIX component of Microsoft Windows NT and Windows
2000 allows local users to execute arbitrary code via
certain parameters, possibly by modifying message length
values and causing a buffer overflow.
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-020
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-020.asp
Reference: CERT:TA04-196A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#647436
Reference:
URL:http://www.kb.cert.org/vuls/id/647436
Reference: XF:win-posix-bo(16590)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16590
Reference: OVAL:oval:org.mitre.oval:def:2166
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2166
Reference: OVAL:oval:org.mitre.oval:def:2847
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2847
Votes:
Name: CVE-2004-0211
Description:
The kernel for Microsoft Windows Server 2003 does not
reset certain values in CPU data structures, which
allows local users to cause a denial of service (system
crash) via a malicious program.
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-032
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference: OVAL:oval:org.mitre.oval:def:4893
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4893
Reference: XF:win2k3-kernel-cpu-dos(16582)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16582
Reference: XF:win-ms04032-patch(17658)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: CERT-VN:VU#119262
Reference:
URL:http://www.kb.cert.org/vuls/id/119262
Votes:
Name: CVE-2004-0212
Description:
Stack-based buffer overflow in the Task Scheduler for
Windows 2000 and XP, and Internet Explorer 6 on Windows
NT 4.0, allows local or remote attackers to execute
arbitrary code via a .job file containing long
parameters, as demonstrated using Internet Explorer and
accessing a .job file on an anonymous share.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040714 Microsoft Windows
Task Scheduler '.job' Stack Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108981273009250&w=2
Reference:
MISC:http://www.ngssoftware.com/advisories/mstaskjob.txt
Reference: BUGTRAQ:20040714 Unchecked buffer in
mstask.dll
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108981403025596&w=2
Reference: MS:MS04-022
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-022.asp
Reference: CERT:TA04-196A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#228028
Reference:
URL:http://www.kb.cert.org/vuls/id/228028
Reference: OVAL:oval:org.mitre.oval:def:1344
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1344
Reference: OVAL:oval:org.mitre.oval:def:1781
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1781
Reference: OVAL:oval:org.mitre.oval:def:1964
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1964
Reference: OVAL:oval:org.mitre.oval:def:3428
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3428
Reference: SECUNIA:12060
Reference:
URL:http://secunia.com/advisories/12060
Reference: XF:win-taskscheduler-bo(16591)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16591
Votes:
Name: CVE-2004-0213
Description:
Utility Manager in Windows 2000 launches winhlp32.exe
while Utility Manager is running with raised privileges,
which allows local users to gain system privileges via a
"Shatter" style attack that sends a Windows message to
cause Utility Manager to launch winhlp32 by directly
accessing the context sensitive help and bypassing the
GUI, then sending another message to winhlp32 in order
to open a user-selected file, a different vulnerability
than CVE-2003-0908.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040713 Microsoft Window
Utility Manager Local Elevation of Privileges
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108975382413405&w=2
Reference: MS:MS04-019
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-019.asp
Reference: CERT:TA04-196A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#868580
Reference:
URL:http://www.kb.cert.org/vuls/id/868580
Reference:
XF:win-utilitymanager-gain-privileges(16592)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16592
Reference: OVAL:oval:org.mitre.oval:def:2495
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2495
Votes:
Name: CVE-2004-0214
Description:
Buffer overflow in Microsoft Internet Explorer and
Explorer on Windows XP SP1, WIndows 2000, Windows 98,
and Windows Me may allow remote malicious servers to
cause a denial of service (application crash) and
possibly execute arbitrary code via long share names, as
demonstrated using Samba.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040425 Microsoft's Explorer
and Internet Explorer long share name buffer overflow.
Reference:
URL:http://seclists.org/lists/bugtraq/2004/Apr/0322.html
Reference: FULLDISC:20040425 Microsoft's Explorer
and Internet Explorer long share name buffer overflow.
Reference:
URL:http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html
Reference: MS:MS04-037
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx
Reference: MSKB:322857
Reference:
URL:http://support.microsoft.com/default.aspx?scid=kb;en-us;322857
Reference: CERT-VN:VU#616200
Reference:
URL:http://www.kb.cert.org/vuls/id/616200
Reference:
MISC:http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html
Reference: BID:10213
Reference:
URL:http://www.securityfocus.com/bid/10213
Reference: OSVDB:5687
Reference: URL:http://www.osvdb.org/5687
Reference: OVAL:oval:org.mitre.oval:def:1601
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1601
Reference: OVAL:oval:org.mitre.oval:def:1749
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1749
Reference: OVAL:oval:org.mitre.oval:def:2638
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2638
Reference: OVAL:oval:org.mitre.oval:def:4345
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4345
Reference: OVAL:oval:org.mitre.oval:def:5307
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5307
Reference: SECTRACK:1011647
Reference:
URL:http://securitytracker.com/id?1011647
Reference: SECUNIA:11482
Reference:
URL:http://secunia.com/advisories/11482/
Reference: XF:win-long-fileshare-bo(15956)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15956
Reference: XF:win-ms04037-patch(17662)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17662
Votes:
Name: CVE-2004-0215
Description:
Microsoft Outlook Express 5.5 and 6 allows attackers to
cause a denial of service (application crash) via a
malformed e-mail header.
Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-018
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-018.asp
Reference: CERT:TA04-196A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#869640
Reference:
URL:http://www.kb.cert.org/vuls/id/869640
Reference:
XF:outlook-malformed-email-header-dos(16585)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16585
Reference: OVAL:oval:org.mitre.oval:def:1950
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1950
Reference: OVAL:oval:org.mitre.oval:def:2137
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2137
Reference: OVAL:oval:org.mitre.oval:def:2657
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2657
Reference: OVAL:oval:org.mitre.oval:def:3376
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3376
Votes:
Name: CVE-2004-0216
Description:
Integer overflow in the Install Engine (inseng.dll) for
Internet Explorer 5.01, 5.5, and 6 allows remote
attackers to execute arbitrary code via a malicious
website or HTML email with a long .CAB file name, which
triggers the integer overflow when calculating a buffer
length and leads to a heap-based buffer overflow.
Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041012 Microsoft Internet
Explorer Install Engine Control Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109760693512754&w=2
Reference: BUGTRAQ:20050119 Microsoft Internet
Explorer Install Engine Control Buffer Overflow
(#NISR19012005a)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110616383332055&w=2
Reference: NTBUGTRAQ:20050119 Microsoft Internet
Explorer Install Engine Control Buffer Overflow
(#NISR19012005a)
Reference:
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=110619893620517&w=2
Reference:
MISC:http://www.ngssoftware.com/advisories/msinsengfull.txt
Reference: MS:MS04-038
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms04-038.asp
Reference: CERT:TA04-293A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-293A.html
Reference: CERT-VN:VU#637760
Reference:
URL:http://www.kb.cert.org/vuls/id/637760
Reference: OVAL:oval:org.mitre.oval:def:5316
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5316
Reference: OVAL:oval:org.mitre.oval:def:5329
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5329
Reference: OVAL:oval:org.mitre.oval:def:6100
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6100
Reference: OVAL:oval:org.mitre.oval:def:6600
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6600
Reference: OVAL:oval:org.mitre.oval:def:7717
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7717
Reference: OVAL:oval:org.mitre.oval:def:7865
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7865
Reference:
XF:ie-installenginectl-setciffile-bo(17620)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17620
Reference: XF:ie-ms04038-patch(17651)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/17651
Votes:
Name: CVE-2004-0217
Description:
The LiveUpdate capability (liveupdate.sh) in Symantec
AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux
allows local users to create or append to arbitrary
files via a symlink attack on /tmp/LiveUpdate.log.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 Possible race
condition in Symantec AntiVirus Scan Engine for Red
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107694800908164&w=2
Reference:
XF:symantec-scanengine-race-condition(15215)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15215
Reference: BID:9662
Reference:
URL:http://www.securityfocus.com/bid/9662
Votes:
ACCEPT(2) Cole, Armstrong
MODIFY(1) Frech
NOOP(1) Cox
REVIEWING(1) Wall
Voter Comments:
Frech> XF:symantec-scanengine-race-condition(15215)
http://xforce.iss.net/xforce/xfdb/15215
Name: CVE-2004-0218
Description:
isakmpd in OpenBSD 3.4 and earlier allows remote
attackers to cause a denial of service (infinite loop)
via an ISAKMP packet with a zero-length payload, as
demonstrated by the Striker ISAKMP Protocol Test Suite.
Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD
isakmpd payload handling denial-of-service
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference:
MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX:
March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#349113
Reference:
URL:http://www.kb.cert.org/vuls/id/349113
Reference: BID:10028
Reference:
URL:http://www.securityfocus.com/bid/10028
Reference: SECTRACK:1009468
Reference:
URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: SECUNIA:11156
Reference:
URL:http://secunia.com/advisories/11156
Reference:
XF:openbsd-isakmp-zerolength-dos(15518)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15518
Votes:
Name: CVE-2004-0219
Description:
isakmpd in OpenBSD 3.4 and earlier allows remote
attackers to cause a denial of service (crash) via an
ISAKMP packet with a malformed IPSEC SA payload, as
demonstrated by the Striker ISAKMP Protocol Test Suite.
Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD
isakmpd payload handling denial-of-service
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference:
MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX:
March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#785945
Reference:
URL:http://www.kb.cert.org/vuls/id/785945
Reference: BID:9907
Reference:
URL:http://www.securityfocus.com/bid/9907
Reference: SECTRACK:1009468
Reference:
URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: XF:openbsd-isakmp-ipsec-dos(15628)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15628
Votes:
Name: CVE-2004-0220
Description:
isakmpd in OpenBSD 3.4 and earlier allows remote
attackers to cause a denial of service via a an ISAKMP
packet with a malformed Cert Request payload, which
causes an integer underflow that is used in a malloc
operation that is not properly handled, as demonstrated
by the Striker ISAKMP Protocol Test Suite.
Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD
isakmpd payload handling denial-of-service
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference:
MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX:
March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#223273
Reference:
URL:http://www.kb.cert.org/vuls/id/223273
Reference: BID:9907
Reference:
URL:http://www.securityfocus.com/bid/9907
Reference: SECTRACK:1009468
Reference:
URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference:
XF:openbsd-isakmp-integer-underflow(15629)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15629
Votes:
Name: CVE-2004-0221
Description:
isakmpd in OpenBSD 3.4 and earlier allows remote
attackers to cause a denial of service (crash) via an
ISAKMP packet with a delete payload containing a large
number of SPIs, which triggers an out-of-bounds read
error, as demonstrated by the Striker ISAKMP Protocol
Test Suite.
Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD
isakmpd payload handling denial-of-service
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference:
MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX:
March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#524497
Reference:
URL:http://www.kb.cert.org/vuls/id/524497
Reference: BID:9907
Reference:
URL:http://www.securityfocus.com/bid/9907
Reference: SECTRACK:1009468
Reference:
URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: XF:openbsd-isakmp-delete-dos(15630)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15630
Votes:
Name: CVE-2004-0222
Description:
Multiple memory leaks in isakmpd in OpenBSD 3.4 and
earlier allow remote attackers to cause a denial of
service (memory exhaustion) via certain ISAKMP packets,
as demonstrated by the Striker ISAKMP Protocol Test
Suite.
Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD
isakmpd payload handling denial-of-service
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference:
MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX:
March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#996177
Reference:
URL:http://www.kb.cert.org/vuls/id/996177
Reference: BID:10028
Reference:
URL:http://www.securityfocus.com/bid/10032
Reference: SECTRACK:1009468
Reference:
URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: XF:openbsd-isakmp-memory-leak(15519)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15519
Votes:
Name: CVE-2004-0223
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040315)
Votes:
Name: CVE-2004-0224
Description:
Multiple buffer overflows in (1) iso2022jp.c or (2)
shiftjis.c for Courier-IMAP before 3.0.0, Courier before
0.45, and SqWebMail before 4.0.0 may allow remote
attackers to execute arbitrary code "when Unicode
character is out of BMP range."
Status: Candidate
Phase: Modified (20050719)
Reference:
CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=5767
Reference: SECUNIA:11087
Reference:
URL:http://secunia.com/advisories/11087/
Reference: BID:9845
Reference:
URL:http://www.securityfocus.com/bid/9845
Reference: XF:courier-codeset-converter-bo(15434)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15434
Votes:
ACCEPT(4) Baker, Cole, Armstrong, Cox
MODIFY(1) Frech
NOOP(3) Green, Christey, Wall
Voter Comments:
Frech> XF:courier-codeset-converter-bo(15434)
http://xforce.iss.net/xforce/xfdb/15434
Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2
Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2
Christey> MISC:http://www.debian.org/security/nonvulns-woody#CVE-2004-0075
CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
Name: CVE-2004-0225
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040316)
Votes:
Name: CVE-2004-0226
Description:
Multiple buffer overflows in Midnight Commander (mc)
before 4.6.0 may allow attackers to cause a denial of
service or execute arbitrary code.
Status: Candidate
Phase: Assigned (20040317)
Reference: DEBIAN:DSA-497
Reference:
URL:http://www.debian.org/security/2004/dsa-497
Reference: MANDRAKE:MDKSA-2004:039
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039
Reference: SUSE:SuSE-SA:2004:012
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_12_mc.html
Reference: REDHAT:RHSA-2004:172
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-172.html
Reference: GENTOO:GLSA-200405-21
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-21.xml
Reference:
XF:midnight-commander-local-privileges(16016)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16016
Votes:
Name: CVE-2004-0227
Description:
Buffer overflow in the zms script in ZoneMinder before
1.19.2 may allow a remote attacker to execute arbitrary
code via a long query string.
Status: Candidate
Phase: Assigned (20040317)
Reference:
CONFIRM:http://www.zoneminder.com/index.php?id=20&type=0&backPID=20&tt_news=29
Reference: XF:zoneminder-zms-bo(16136)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16136
Reference: BID:10340
Reference:
URL:http://www.securityfocus.com/bid/10340
Votes:
Name: CVE-2004-0228
Description:
Integer signedness error in the cpufreq proc handler
(cpufreq_procctl) in Linux kernel 2.6 allows local users
to gain privileges.
Status: Candidate
Phase: Assigned (20040317)
Reference: CONECTIVA:CLA-2004:852
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000852
Reference: FEDORA:FEDORA-2004-111
Reference:
URL:http://fedoranews.org/updates/FEDORA-2004-111.shtml
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:050
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:050
Reference: SUSE:SuSE-SA:2004:010
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_10_kernel.html
Reference: SECUNIA:11429
Reference:
URL:http://secunia.com/advisories/11429
Reference: SECUNIA:11464
Reference:
URL:http://secunia.com/advisories/11464
Reference: SECUNIA:11486
Reference:
URL:http://secunia.com/advisories/11486
Reference: SECUNIA:11491
Reference:
URL:http://secunia.com/advisories/11491
Reference: SECUNIA:11683
Reference:
URL:http://secunia.com/advisories/11683
Reference:
XF:linux-cpufreq-info-disclosure(15951)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15951
Votes:
Name: CVE-2004-0229
Description:
The framebuffer driver in Linux kernel 2.6.x does not
properly use the fb_copy_cmap function, with unknown
impact.
Status: Candidate
Phase: Assigned (20040317)
Reference: CONECTIVA:CLA-2004:852
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000852
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:037
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:037
Reference: SUSE:SuSE-SA:2004:010
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_10_kernel.html
Reference: BID:10211
Reference:
URL:http://www.securityfocus.com/bid/10211
Reference: XF:linux-framebuffer(15974)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15974
Votes:
Name: CVE-2004-0230
Description:
TCP, when using a large Window Size, makes it easier for
remote attackers to guess sequence numbers and cause a
denial of service (connection loss) to persistent TCP
connections by repeatedly injecting a TCP RST packet,
especially in protocols that use long-lived connections,
such as BGP.
Status: Candidate
Phase: Assigned (20040317)
Reference: CISCO:20040420 TCP Vulnerabilities in
Multiple IOS-Based Cisco Products
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml
Reference:
CONFIRM:http://www.juniper.net/support/alert.html
Reference: HP:SSRT4696
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108506952116653&w=2
Reference: HP:HPSBST02161
Reference:
URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded
Reference: HP:SSRT061264
Reference:
URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded
Reference: MS:MS05-019
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx
Reference: MS:MS06-064
Reference:
URL:http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx
Reference: NETBSD:NetBSD-SA2004-006
Reference:
URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc
Reference: SCO:SCOSA-2005.3
Reference:
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt
Reference: SCO:SCOSA-2005.9
Reference:
URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt
Reference: SCO:SCOSA-2005.14
Reference:
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt
Reference: SGI:20040403-01-A
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc
Reference: CERT:TA04-111A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-111A.html
Reference: CERT-VN:VU#415294
Reference:
URL:http://www.kb.cert.org/vuls/id/415294
Reference:
MISC:http://www.uniras.gov.uk/vuls/2004/236929/index.htm
Reference: BUGTRAQ:20040425 Perl code exploting
TCP not checking RST ACK.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108302060014745&w=2
Reference: BID:10183
Reference:
URL:http://www.securityfocus.com/bid/10183
Reference: FRSIRT:ADV-2006-3983
Reference:
URL:http://www.frsirt.com/english/advisories/2006/3983
Reference: OSVDB:4030
Reference: URL:http://www.osvdb.org/4030
Reference: OVAL:oval:org.mitre.oval:def:4791
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4791
Reference: OVAL:oval:org.mitre.oval:def:2689
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2689
Reference: OVAL:oval:org.mitre.oval:def:3508
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3508
Reference: OVAL:oval:org.mitre.oval:def:270
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:270
Reference: SECUNIA:11440
Reference:
URL:http://secunia.com/advisories/11440
Reference: SECUNIA:11458
Reference:
URL:http://secunia.com/advisories/11458
Reference: SECUNIA:22341
Reference:
URL:http://secunia.com/advisories/22341
Reference: XF:tcp-rst-dos(15886)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15886
Votes:
Name: CVE-2004-0231
Description:
Multiple vulnerabilities in Midnight Commander (mc)
before 4.6.0, with unknown impact, related to "Insecure
temporary file and directory creations."
Status: Candidate
Phase: Assigned (20040317)
Reference: DEBIAN:DSA-497
Reference:
URL:http://www.debian.org/security/2004/dsa-497
Reference: MANDRAKE:MDKSA-2004:039
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039
Reference: SUSE:SuSE-SA:2004:012
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_12_mc.html
Reference: REDHAT:RHSA-2004:172
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-172.html
Reference: GENTOO:GLSA-200405-21
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-21.xml
Reference:
XF:midnight-commander-insecure-files(16020)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16020
Votes:
Name: CVE-2004-0232
Description:
Multiple format string vulnerabilities in Midnight
Commander (mc) before 4.6.0 may allow attackers to cause
a denial of service or execute arbitrary code.
Status: Candidate
Phase: Assigned (20040317)
Reference: DEBIAN:DSA-497
Reference:
URL:http://www.debian.org/security/2004/dsa-497
Reference: MANDRAKE:MDKSA-2004:039
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039
Reference: SUSE:SuSE-SA:2004:012
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_12_mc.html
Reference: REDHAT:RHSA-2004:172
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-172.html
Reference: GENTOO:GLSA-200405-21
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-21.xml
Reference:
XF:midnight-commander-format-string(16021)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16021
Votes:
Name: CVE-2004-0233
Description:
Utempter allows device names that contain .. (dot dot)
directory traversal sequences, which allows local users
to overwrite arbitrary files via a symlink attack on
device names in combination with an application that
trusts the utmp or wtmp files.
Status: Candidate
Phase: Assigned (20040317)
Reference: MANDRAKE:MDKSA-2004:031
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:031
Reference: REDHAT:RHSA-2004:174
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-174.html
Reference: REDHAT:RHSA-2004:175
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-175.html
Reference: SLACKWARE:SSA:2004-110
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404389
Reference: GENTOO:GLSA-200405-05
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-05.xml
Reference: BID:10178
Reference:
URL:http://www.securityfocus.com/bid/10178
Reference: XF:utemper-symlink(15904)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15904
Reference: OVAL:oval:org.mitre.oval:def:979
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:979
Votes:
Name: CVE-2004-0234
Description:
Multiple stack-based buffer overflows in the get_header
function in header.c for LHA 1.14, as used in products
such as Barracuda Spam Firewall, allow remote attackers
or local users to execute arbitrary code via long
directory or file names in an LHA archive, which
triggers the overflow when testing or extracting the
archive.
Status: Candidate
Phase: Assigned (20040317)
Reference: FULLDISC:20040501 LHa buffer overflows
and directory traversal problems
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html
Reference: FULLDISC:20040502 Lha local stack
overflow Proof Of Concept Code
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html
Reference: BUGTRAQ:20040510 [Ulf Harnhammar]: LHA
Advisory + Patch
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108422737918885&w=2
Reference: BUGTRAQ:20060403 Barracuda LHA
archiver security bug leads to remote compromise
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html
Reference:
MISC:http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt
Reference: CONECTIVA:CLA-2004:840
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000840
Reference: DEBIAN:DSA-515
Reference:
URL:http://www.debian.org/security/2004/dsa-515
Reference: FEDORA:FLSA:1833
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1833
Reference: REDHAT:RHSA-2004:178
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-178.html
Reference: REDHAT:RHSA-2004:179
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-179.html
Reference: GENTOO:GLSA-200405-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-02.xml
Reference: FEDORA:FEDORA-2004-119
Reference:
URL:http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html
Reference: BID:10243
Reference:
URL:http://www.securityfocus.com/bid/10243
Reference: FRSIRT:ADV-2006-1220
Reference:
URL:http://www.frsirt.com/english/advisories/2006/1220
Reference: OSVDB:5753
Reference: URL:http://www.osvdb.org/5753
Reference: OSVDB:5754
Reference: URL:http://www.osvdb.org/5754
Reference: OVAL:oval:org.mitre.oval:def:977
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:977
Reference: SECTRACK:1015866
Reference:
URL:http://securitytracker.com/id?1015866
Reference: SECUNIA:19514
Reference:
URL:http://secunia.com/advisories/19514
Reference: XF:lha-multiple-bo(16012)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16012
Votes:
Name: CVE-2004-0235
Description:
Multiple directory traversal vulnerabilities in LHA 1.14
allow remote attackers or local users to create
arbitrary files via an LHA archive containing filenames
with (1) .. sequences or (2) absolute pathnames with
double leading slashes ("//absolute/path").
Status: Candidate
Phase: Assigned (20040317)
Reference: FULLDISC:20040501 LHa buffer overflows
and directory traversal problems
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html
Reference: BUGTRAQ:20040510 [Ulf Harnhammar]: LHA
Advisory + Patch
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108422737918885&w=2
Reference: CONECTIVA:CLA-2004:840
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000840
Reference: DEBIAN:DSA-515
Reference:
URL:http://www.debian.org/security/2004/dsa-515
Reference: FEDORA:FLSA:1833
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1833
Reference: REDHAT:RHSA-2004:178
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-178.html
Reference: REDHAT:RHSA-2004:179
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-179.html
Reference: GENTOO:GLSA-200405-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-02.xml
Reference: FEDORA:FEDORA-2004-119
Reference:
URL:http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html
Reference: BID:10243
Reference:
URL:http://www.securityfocus.com/bid/10243
Reference: XF:lha-directory-traversal(16013)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16013
Reference: OVAL:oval:org.mitre.oval:def:978
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:978
Votes:
Name: CVE-2004-0236
Description:
SQL injection vulnerability in login.asp in thePHOTOtool
allows remote attackers to gain unauthorized access via
the password field.
Status: Candidate
Phase: Modified (20050710)
Reference: BUGTRAQ:20040131 Advisory !
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107576894019530&w=2
Reference: BID:9884
Reference:
URL:http://www.securityfocus.com/bid/9884
Reference:
XF:thephototool-login-sql-injection(15007)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15007
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0237
Description:
Directory traversal vulnerability in index.php in Aprox
PHP Portal allows remote attackers to read arbitrary
files via a full pathname in the show parameter.
Status: Candidate
Phase: Modified (20071031)
Reference: BUGTRAQ:20040131 Directory Traversal
in Aprox PHP Portal.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577555527321&w=2
Reference: BID:9540
Reference:
URL:http://www.securityfocus.com/bid/9540
Reference: OSVDB:10859
Reference: URL:http://www.osvdb.org/10859
Reference: SECTRACK:1008915
Reference:
URL:http://securitytracker.com/id?1008915
Reference:
XF:aproxphpportal-index-directory-traversal(15014)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15014
Votes:
NOOP(5) Green, Wall, Cole, Armstrong, Cox
Name: CVE-2004-0238
Description:
Multiple buffer overflows in Overkill (0verkill)
0.15pre3 might allow local users to execute arbitrary
code in the client via a long HOME environment variable
in the (1) load_cfg and (2) save_cfg functions; possibly
allow remote attackers to execute arbitrary code via
long strings to (3) the send_message function; and, in
the server, via (4) the parse_command_line function.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040202 0verkill - little
simple vulnerability.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577335424509&w=2
Reference: FULLDISC:20040202 0verkill - little
simple vulnerability.
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html
Reference:
MISC:http://www.securiteam.com/securitynews/5AP010KC0C.html
Reference: BID:9550
Reference:
URL:http://www.securityfocus.com/bid/9550
Reference: XF:overkill-client-multiple-bo(14999)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14999
Reference:
XF:overkill-server-parsecommandline-bo(15000)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15000
Votes:
ACCEPT(1) Armstrong
NOOP(3) Wall, Cole, Cox
Name: CVE-2004-0239
Description:
SQL injection vulnerability in showphoto.php in
PhotoPost PHP Pro 4.6 and earlier allows remote
attackers to gain unauthorized access via the photo
variable.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040202 ZH2004-03SA (security
advisory): Photopost PHP Pro 4.6 Sql
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582512023998&w=2
Reference:
MISC:http://www.securiteam.com/securitynews/5KP010UC0W.html
Reference: XF:photopostphp-sql-injection(15008)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15008
Reference: BID:9557
Reference:
URL:http://www.securityfocus.com/bid/9557
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0240
Description:
Directory traversal vulnerability in X-Cart 3.4.3 allows
remote attackers to view arbitrary files via a .. (dot
dot) in the shop_closed_file argument to auth.php.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 X-Cart vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582648326448&w=2
Reference:
XF:xcart-dotdot-directory-traversal(15033)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15033
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0241
Description:
X-Cart 3.4.3 allows remote attackers to execute
arbitrary commands via the perl_binary argument in (1)
upgrade.php or (2) general.php.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 X-Cart vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582648326448&w=2
Reference:
XF:xcart-perlbinary-execute-commands(15034)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15034
Reference: BID:9560
Reference:
URL:http://www.securityfocus.com/bid/9560
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0242
Description:
X-Cart 3.4.3 allows remote attackers to gain sensitive
information via a mode parameter with (1) phpinfo
command or (2) perlinfo command.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 X-Cart vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582648326448&w=2
Reference:
XF:xcart-generalphp-obtain-information(15036)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15036
Reference: BID:9563
Reference:
URL:http://www.securityfocus.com/bid/9563
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0243
Description:
AIX 4.3.3 through AIX 5.1, when direct remote login is
disabled, displays a different message if the password
is correct, which allows remote attackers to guess the
password via brute force methods.
Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040203 Re: sqwebmail web
login
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107583269206044&w=2
Reference: BUGTRAQ:20040206 AIX password
enumeration possible
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-02/0313.html
Reference: XF:aix-password-enumeration(15172)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15172
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0244
Description:
Cisco 6000, 6500, and 7600 series systems with
Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN
or OSM module allow local users to cause a denial of
service (hang or reset) by sending a layer 2 frame
packet that encapsulates a layer 3 packet, but has
inconsistent length values with that packet.
Status: Candidate
Phase: Modified (20050510)
Reference: CISCO:20040203 Cisco 6000/6500/7600
Crafted Layer 2 Frame Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040203-cat6k.shtml
Reference: CERT-VN:VU#810062
Reference:
URL:http://www.kb.cert.org/vuls/id/810062
Reference: SECUNIA:10780
Reference:
URL:http://secunia.com/advisories/10780
Reference: BID:9562
Reference:
URL:http://www.securityfocus.com/bid/9562
Reference: XF:cisco-malformed-frame-dos(15013)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15013
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
NOOP(2) Christey, Cox
Voter Comments:
Christey> CERT-VN:VU#810062
Name: CVE-2004-0245
Description:
Web Crossing 4.x and 5.x allows remote attackers to
cause a denial of service (crash) by sending a HTTP POST
request with a large or negative Content-Length, which
causes an integer divide-by-zero.
Status: Candidate
Phase: Modified (20050710)
Reference: BUGTRAQ:20040203 Web Crossing 4.x/5.x
Denial of Service Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107586518120516&w=2
Reference: BID:9576
Reference:
URL:http://www.securityfocus.com/bid/9576
Reference:
XF:webcrossing-contentlength-post-dos(15022)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15022
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0246
Description:
Multiple PHP remote file inclusion vulnerabilities in
(1) fonctions.lib.php, (2) derniers_commentaires.php,
and (3) admin.php in Les Commentaires 2.0 allow remote
attackers to execute arbitrary PHP code via the rep
parameter.
Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040203 Les Commentaires
(PHP) Include file
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107584083719763&w=2
Reference: BID:9536
Reference:
URL:http://www.securityfocus.com/bid/9536
Reference: SECUNIA:10768
Reference:
URL:http://secunia.com/advisories/10768/
Reference:
XF:lescommentaires-multiple-file-include(15010)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15010
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0247
Description:
The client and server of Chaser 1.50 and earlier allow
remote attackers to cause a denial of service (crash via
exception) via a UDP packet with a length field that is
greater than the actual data length, which causes Chaser
to read unexpected memory.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 Remote crash of
Chaser game <= 1.50
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107584109420084&w=2
Reference: BID:9567
Reference:
URL:http://www.securityfocus.com/bid/9567
Reference: XF:chaser-memory-dos(15031)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15031
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0248
Description:
Cross-site scripting vulnerability (XSS) in PHPX 3.2.3
allows remote attackers to execute arbitrary script as
other users by injecting arbitrary HTML or script into
(1) keywords argument of main.inc.php, (2) body argument
of help.inc.php, or (3) the subject field in Personal
Messages and Forum.
Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040203 Multiple
Vulnerabilities in PHPX
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107586932324901&w=2
Reference: BID:9569
Reference:
URL:http://www.securityfocus.com/bid/9569
Reference: SECUNIA:10797
Reference:
URL:http://secunia.com/advisories/10797/
Reference: XF:phpx-subject-html-injection(15050)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15050
Reference: XF:phpx-main-help-xss(15051)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15051
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0249
Description:
PHPX 2.0 through 3.2.4 allows remote attackers to gain
access to other accounts by modifying the cookie's PXL
variable to reference another userID.
Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040203 Multiple
Vulnerabilities in PHPX
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107586932324901&w=2
Reference: BUGTRAQ:20040316 PHPX 2.x - 3.2.4
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0154.html
Reference: BID:9569
Reference:
URL:http://www.securityfocus.com/bid/9569
Reference: SECUNIA:10797
Reference:
URL:http://secunia.com/advisories/10797/
Reference: XF:phpx-session-hijack(15512)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15512
Reference:
XF:phpx-cookie-account-hijacking(15052)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15052
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0250
Description:
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and
earlier allows remote attackers to gain privileges via
(1) the product parameter in showproduct.php or (2) the
cat parameter in showcat.php.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040204 ZH2004-04SA (security
advisory): Multiple Sql Injection
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107593114909696&w=2
Reference:
MISC:http://www.zone-h.org/en/advisories/read/id=3864/
Reference: BID:9557
Reference:
URL:http://www.securityfocus.com/bid/9557
Reference: XF:photopostphp-sql-injection(15008)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15008
Votes:
ACCEPT(1) Armstrong
NOOP(3) Wall, Cole, Cox
Name: CVE-2004-0251
Description:
Cross-site scripting (XSS) vulnerability in rxgoogle.cgi
allows remote attackers to execute arbitrary script as
other users via the query parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040204 rxgoogle.cgi XSS
Vulnerability.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107594183924958&w=2
Reference: XF:rxgoogle-query-xss(15043)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15043
Reference: BID:9575
Reference:
URL:http://www.securityfocus.com/bid/9575
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0252
Description:
TYPSoft FTP Server 1.10 allows remote attackers to cause
a denial of service (CPU consumption) via an empty USER
name.
Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040204 TYPSoft FTP Server
1.10 may be crashed
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107591511716707&w=2
Reference: BID:9573
Reference:
URL:http://www.securityfocus.com/bid/9573
Reference: SECTRACK:1008943
Reference:
URL:http://www.securitytracker.com/alerts/2004/Feb/1008943.html
Reference: XF:typsoft-empty-username-dos(15048)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15048
Votes:
ACCEPT(1) Armstrong
NOOP(3) Wall, Cole, Cox
Name: CVE-2004-0253
Description:
IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote
attackers to execute arbitrary programs or cause a
denial of service via certain SQL code, possibly due to
a SQL injection vulnerability.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 IBM cloudscape SQL
Database (DB2J) vulnerable to remote command
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107604065819233&w=2
Reference: BID:9583
Reference:
URL:http://www.securityfocus.com/bid/9583
Reference: XF:cloudscape-sql-injection(15067)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15067
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0254
Description:
Cross-site scripting (XSS) vulnerability in Discuz!
Board 2.x and 3.x allows remote attackers to execute
arbitrary script as other users via an img tag.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Possible Cross Site
Scripting in Discuz! Board
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107606726417150&w=2
Reference: BID:9584
Reference:
URL:http://www.securityfocus.com/bid/9584
Reference: XF:discuzboard-image-tag-xss(15066)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15066
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0255
Description:
Xlight 1.52, with log to screen enabled, allows remote
attackers to cause a denial of service by requesting a
long directory consisting of . (dot) and / (slash)
characters, which causes the server to crash when the
administrator views the log file, possibly triggering a
buffer overflow.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Remote crash Xlight
ftp server 1.52
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107605633904122&w=2
Reference: XF:xlight-long-string-dos(15064)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15064
Reference: BID:9585
Reference:
URL:http://www.securityfocus.com/bid/9585
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
REVIEWING(1) Christey
Voter Comments:
Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40
In the above URL, the vendor says that only one of 3 bugs
reported in February 2004 were an "actual server bug," and the other 2
"traced back into windows' dll and they won't happen if windows
service pack is installed.
The "actual server bug" is CVE-2004-0287. The demonstration
for *this* issue shows that the application breaks in comctl32.dll.
So, this candidate may be erroneous, and an interesting side effect of
another bug that's not related to xlight at all.
Thus, this candidate may need to be REJECTED.
Name: CVE-2004-0258
Description:
Multiple buffer overflows in RealOne Player, RealOne
Player 2.0, RealOne Enterprise Desktop, and RealPlayer
Enterprise allow remote attackers to execute arbitrary
code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM
or (5) .SMIL files.
Status: Candidate
Phase: Proposed (20040318)
Reference: VULNWATCH:20040204 [VulnWatch]
Multiple File Format Vulnerabilities (Overruns) in
REALOne & RealPlayer
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0027.html
Reference: BUGTRAQ:20040204 Multiple File Format
Vulnerabilities (Overruns) in REALOne & RealPlayer
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107608748813559&w=2
Reference:
MISC:http://www.nextgenss.com/advisories/realone.txt
Reference:
CONFIRM:http://www.service.real.com/help/faq/security/040123_player/EN/
Reference: CERT-VN:VU#473814
Reference:
URL:http://www.kb.cert.org/vuls/id/473814
Reference: CIAC:O-075
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-075.shtml
Reference: BID:9579
Reference:
URL:http://www.securityfocus.com/bid/9579
Reference:
XF:realoneplayer-multiple-file-bo(15040)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15040
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
NOOP(1) Cox
Name: CVE-2004-0259
Description:
The check_referer() function in Formmail.php 5.0 and
earlier allows remote attackers to bypass access
restrictions via an empty or spoofed HTTP Referer, as
demonstrated using an application on the same web server
that contains a cross-site scripting (XSS) issue.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040206 formmail (PHP) Upload
file using CSS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107619109629629&w=2
Reference: XF:jack-formmail-file-upload(15079)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15079
Reference: BID:9591
Reference:
URL:http://www.securityfocus.com/bid/9591
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0260
Description:
The AddToMailingList function in CactuSoft CactuShop 5.0
Lite contains a backdoor that allows remote attackers to
delete arbitrary files via an email address that starts
with |||.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040206 CactuSoft CactuShop
5.0 Lite shopping cart software backdoor
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107619501815888&w=2
Reference: FULLDISC:20040206 CactuSoft CactuShop
5.0 Lite shopping cart software backdoor
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016819.html
Reference: XF:cactushoplite-backdoor(15063)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15063
Reference: BID:9589
Reference:
URL:http://www.securityfocus.com/bid/9589
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0262
Description:
Stack-based buffer overflow in The Palace 3.5 and
earlier client allows remote attackers to execute
arbitrary code via a link to a palace:// url followed by
a long server address string.
Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040207 The Palace 3.x
(Client) Stack Overflow Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634556632195&w=2
Reference: VULNWATCH:20040207 The Palace 3.x
(Client) Stack Overflow Vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0033.html
Reference:
MISC:http://www.elitehaven.net/thepalace.txt
Reference: XF:palace-server-address-bo(15074)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15074
Reference: BID:9602
Reference:
URL:http://www.securityfocus.com/bid/9602
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0264
Description:
palmhttpd for PalmOS allows remote attackers to cause a
denial of service (crash) by establishing two
simultaneous HTTP connections, which exceeds the PalmOS
accept queue.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040208 PalmOS httpd accept()
queue overflow DoS vulnerability.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634638201570&w=2
Reference: XF:palmhttpd-accept-bo(15090)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15090
Reference: BID:9608
Reference:
URL:http://www.securityfocus.com/bid/9608
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0265
Description:
Cross-site scripting (XSS) vulnerability in modules.php
for Php-Nuke 6.x-7.1.0 allows remote attackers to
execute arbitrary script as other users via URL-encoded
(1) title or (2) fname parameters in the News or Reviews
modules.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040208 [waraxe-2004-SA#002]
- Cross-Site Scripting (XSS) in Php-Nuke 7.1.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634727520936&w=2
Reference: XF:phpnuke-mulitple-xss(15076)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15076
Reference: BID:9605
Reference:
URL:http://www.securityfocus.com/bid/9605
Reference: BID:9613
Reference:
URL:http://www.securityfocus.com/bid/9613
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0266
Description:
SQL injection vulnerability in the "public message"
capability (public_message) for Php-Nuke 6.x to 7.1.0
allows remote attackers obtain the administrator
password via the c_mid parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040208 [waraxe-2004-SA#003]
- SQL injection in Php-Nuke 7.1.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635110327066&w=2
Reference:
XF:phpnuke-publicmessage-sql-injection(15080)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15080
Reference: BID:9615
Reference:
URL:http://www.securityfocus.com/bid/9615
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0267
Description:
The (1) inoregupdate, (2) uniftest, or (3) unimove
scripts in eTrust InoculateIT for Linux 6.0 allow local
users to overwrite arbitrary files via a symlink attack
on files in /tmp.
Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040209 [local problems]
eTrust Virus Protection 6.0 InoculateIT for linux
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635584431518&w=2
Reference:
MISC:http://www.excluded.org/advisories/advisory10.txt
Reference: BID:9616
Reference:
URL:http://www.securityfocus.com/bid/9616
Reference: OSVDB:4735
Reference: URL:http://www.osvdb.org/4735
Reference: OSVDB:4855
Reference: URL:http://www.osvdb.org/4855
Reference: OSVDB:4856
Reference: URL:http://www.osvdb.org/4856
Reference: SECUNIA:10833
Reference:
URL:http://secunia.com/advisories/10833
Reference: XF:etrust-inoculateit-symlink(15102)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15102
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0268
Description:
Multiple buffer overflows in EvolutionX 3921 and 3935
allow remote attackers to cause a denial of service
(hang) via (1) a long cd command to the FTP server, or
(2) a long dir command to the telnet server.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 XBOX EvolutionX ftp
'cd' command and telnet 'dir' buffer overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643394724891&w=2
Reference: FULLDISC:20040210 XBOX EvolutionX ftp
'cd' command and telnet 'dir' buffer overflow
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016988.html
Reference: XF:evolutionx-command-line-dos(15104)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15104
Reference: BID:9631
Reference:
URL:http://www.securityfocus.com/bid/9631
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0269
Description:
SQL injection vulnerability in PHP-Nuke 6.9 and earlier,
and possibly 7.x, allows remote attackers to inject
arbitrary SQL code and gain sensitive information via
(1) the category variable in the Search module or (2)
the admin variable in the Web_Links module.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 [SCAN Associates Sdn
Bhd Security Advisory] PHPNuke 6.9 > and below SQL
Injection in multiple module
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643348117646&w=2
Reference:
MISC:http://www.scan-associates.net/papers/phpnuke69.txt
Reference:
XF:phpnuke-modules-sql-injection(15115)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15115
Reference: BID:9630
Reference:
URL:http://www.securityfocus.com/bid/9630
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0271
Description:
Multiple cross-site scripting vulnerabilities (XSS) in
MaxWebPortal allow remote attackers to execute arbitrary
web script as other users via (1) the sub_name parameter
of dl_showall.asp, (2) the SendTo parameter in Personal
Messages, (3) the HTTP_REFERER for down.asp, or (4) the
image name of an Avatar in the register form.
Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040210 XSS, Sql Injection
and Avatar ScriptCode Injection in MaxWebPortal
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643014606515&w=2
Reference: BID:9625
Reference:
URL:http://www.securityfocus.com/bid/9625
Reference: XF:maxwebportal-multiple-xss(15120)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15120
Reference: XF:maxwebportal-register-xss(15122)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15122
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0272
Description:
SQL injection vulnerability in MaxWebPortal allows
remote attackers to inject arbitrary SQL code and gain
sensitive information via the SendTo parameter in
Personal Messages.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 XSS, Sql Injection
and Avatar ScriptCode Injection in MaxWebPortal
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643014606515&w=2
Reference:
XF:maxwebportal-personalmesssages-sql-injection(15121)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15121
Reference: BID:9625
Reference:
URL:http://www.securityfocus.com/bid/9625
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0275
Description:
SQL injection vulnerability in calendar_download.php in
BosDates 3.2 and earlier allows remote attackers to
obtain sensitive information and gain access via the
calendar parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040211 ZH2004-05SA (security
advisory): Sql Injection Vulnerability in BosDates
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107651618613575&w=2
Reference:
MISC:http://www.zone-h.org/en/advisories/read/id=3925/
Reference:
XF:bosdates-calendar-sql-injection(15133)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15133
Reference: BID:9639
Reference:
URL:http://www.securityfocus.com/bid/9639
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0277
Description:
Format string vulnerability in Dream FTP 1.02 allows
remote attackers to cause a denial of service (crash)
and possibly execute arbitrary code via format string
specifiers in the username.
Status: Candidate
Phase: Proposed (20040318)
Reference: FULLDISC:20040207 DreamFTP Server 1.02
Buffer Overflow
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016871.html
Reference:
MISC:http://www.security-protocols.com/modules.php?name=News&file=article&sid=1722
Reference: BUGTRAQ:20040211 Re: [Full-Disclosure]
DreamFTP Server 1.02 Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107656166402882&w=2
Reference:
XF:dreamftp-username-format-string(15070)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15070
Reference: BID:9600
Reference:
URL:http://www.securityfocus.com/bid/9600
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0278
Description:
Ratbag game engine, as used in products such as Dirt
Track Racing, Leadfoot, and World of Outlaws Spring
Cars, allows remote attackers to cause a denial of
service (CPU consumption) via a TCP packet that
specifies the length of data to read and then sends a
second TCP packet that contains less data than
specified, which causes Ratbag to repeatedly check the
socket for more data.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040211 Denial of Service in
Ratbag's game engine
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107655269820530&w=2
Reference: XF:ratbag-data-length-dos(15188)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15188
Reference: BID:9644
Reference:
URL:http://www.securityfocus.com/bid/9644
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0279
Description:
AIM Sniff (aimSniff.pl) 0.9b allows local users to
overwrite arbitrary files via a symlink attack on
/tmp/AS.log.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040212 aimSniff.pl file
"deletion" (local)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107662243303439&w=2
Reference: XF:aim-sniff-symlink(15199)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15199
Reference: BID:9653
Reference:
URL:http://www.securityfocus.com/bid/9653
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0280
Description:
Caucho Technology Resin 2.1.12 allows remote attackers
to view JSP source via an HTTP request to a .jsp file
that ends in a "%20" (encoded space character), e.g.
index.jsp%20.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Apache Http Server
Reveals Script Source Code to Remote Users And Any Users
Can Access Resin Forbidden Directory ("/WEB-INF/")
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635084830547&w=2
Reference: BID:9614
Reference:
URL:http://www.securityfocus.com/bid/9614
Reference: XF:resin-source-disclosure(15085)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15085
Votes:
ACCEPT(1) Cole
NOOP(3) Wall, Armstrong, Cox
Name: CVE-2004-0281
Description:
Caucho Technology Resin 2.1.12 allows remote attackers
to gain sensitive information and view the contents of
the /WEB-INF/ directory via an HTTP request for
"WEB-INF..", which is equivalent to "WEB-INF" in
Windows.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Apache Http Server
Reveals Script Source Code to Remote Users And Any Users
Can Access Resin Forbidden Directory ("/WEB-INF/")
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635084830547&w=2
Reference: BID:9617
Reference:
URL:http://www.securityfocus.com/bid/9617
Reference:
XF:resin-dotdot-directory-traversal(15087)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15087
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0282
Description:
Crob FTP daemon 3.5.2 allows remote attackers to cause a
denial of service (crash) by repeatedly connecting to
and disconnecting from the server.
Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040212 crob ftpd Denial of
Service
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107665920909374&w=2
Reference: BID:9651
Reference:
URL:http://www.securityfocus.com/bid/9651
Reference: OSVDB:6621
Reference: URL:http://www.osvdb.org/6621
Reference: SECUNIA:10882
Reference:
URL:http://secunia.com/advisories/10882
Reference:
XF:crob-multiple-connections-dos(15201)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15201
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0283
Description:
Mailmgr 1.2.3 allows local users to overwrite arbitrary
files via a symlink attack on (1) /tmp/mailmgr.unsort,
(2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040212 Symlink
vulnerabilities in mailmgr
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107665013714517&w=2
Reference: XF:mailmgr-insecure-temp-directory
(15203)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15203
Reference: BID:9654
Reference:
URL:http://www.securityfocus.com/bid/9654
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0284
Description:
Microsoft Internet Explorer 6.0, Outlook 2002, and
Outlook 2003 allow remote attackers to cause a denial of
service (CPU consumption), if "Do not save encrypted
pages to disk" is disabled, via a web site or HTML
e-mail that contains two null characters (%00) after the
host name.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 ASPR #2004-01-20-1:
Internet Explorer/Outlook double null character DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643134712133&w=2
Reference: XF:ie-host-null-dos(15127)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15127
Reference: BID:9629
Reference:
URL:http://www.securityfocus.com/bid/9629
Votes:
ACCEPT(1) Cole
NOOP(3) Christey, Armstrong, Cox
REVIEWING(1) Wall
Voter Comments:
Christey> MISC:http://www.acrossecurity.com/aspr/ASPR-2004-01-20-1-PUB.txt
Name: CVE-2004-0285
Description:
PHP remote file inclusion vulnerabilities in
include/footer.inc.php in (1) AllMyVisitors, (2)
AllMyLinks, and (3) AllMyGuests allow remote attackers
to execute arbitrary PHP code via a URL in the
_AMVconfig[cfg_serverpath] parameter.
Status: Candidate
Phase: Modified (20070123)
Reference: BUGTRAQ:20040214 AllMyVisitors PHP
Code Injection vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696235424865&w=2
Reference: BUGTRAQ:20040214 AllMyGuests PHP Code
Injection vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696209514155&w=2
Reference: BUGTRAQ:20040214 AllMyLinks PHP Code
Injection vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696291728750&w=2
Reference: BID:9664
Reference:
URL:http://www.securityfocus.com/bid/9664
Reference: OSVDB:6721
Reference: URL:http://www.osvdb.org/6721
Reference: XF:allmyvisitors-file-include(15228)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15228
Reference: XF:allmyguests-php-file-include(15227)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15227
Reference: XF:allmylinks-file-include(15226)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15226
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0286
Description:
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows
remote attackers to cause a denial of service (crash)
and possibly execute arbitrary code via a long username.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040215 buffer overflow in
Robot FTP Server
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696194306878&w=2
Reference: XF:robot-username-bo(15225)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15225
Reference: BID:9672
Reference:
URL:http://www.securityfocus.com/bid/9672
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0287
Description:
Xlight FTP server 1.52 allows remote authenticated users
to cause a denial of service (crash) via a RETR command
with a long argument containing a large number of /
(slash) characters, possibly triggering a buffer
overflow.
Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040215 Xlight ftp server
1.52 RETR bug
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695172917263&w=2
Reference: XF:xlight-retr-dos(15220)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15220
Reference: BID:9668
Reference:
URL:http://www.securityfocus.com/bid/9668
Votes:
NOOP(5) Christey, Wall, Cole, Armstrong, Cox
Voter Comments:
Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32
and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says
that this was fixed in 1.55.
Also, DELREF BID:9627 - it's not a clean match.
Instead, ADDREF BID:9668
Name: CVE-2004-0288
Description:
Buffer overflow in the UdmDocToTextBuf function in
mnoGoSearch 3.2.13 through 3.2.15 could allow remote
attackers to execute arbitrary code by indexing a large
document.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040215 Buffer overflow in
mnoGoSearch
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695139930726&w=2
Reference:
XF:mnogosearch-udmdoctotextbuf-bo(15209)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15209
Reference: BID:9667
Reference:
URL:http://www.securityfocus.com/bid/9667
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0289
Description:
Buffer overflow in sdbscan in SignatureDB 0.1.1 allows
local users to cause a denial of service (segmentation
fault) via a database file that contains a large key
parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040215 problems with
database files in 'SignatureDB'
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695113832648&w=2
Reference: BID:9661
Reference:
URL:http://www.securityfocus.com/bid/9661
Reference: XF:signaturedb-sdbscan-bo(15217)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15217
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0290
Description:
Buffer overflow in Purge Jihad 2.0.1 and earlier allows
remote game servers to execute arbitrary code via an
information packet that contains large (1) battle type
and (2) map name fields.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 Broadcast client
buffer-overflow in Purge Jihad <= 2.0.1
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695064204362&w=2
Reference:
CONFIRM:http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167
Reference: BID:9671
Reference:
URL:http://www.securityfocus.com/bid/9671
Reference: XF:purge-battletype-map-bo(15216)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15216
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0291
Description:
SQL injection vulnerability in post.php for YaBB SE
1.5.4 and 1.5.5 allows remote attackers to obtain hashed
passwords via the quote parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 Another YabbSE SQL
Injection
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696318522985&w=2
Reference: BID:9674
Reference:
URL:http://www.securityfocus.com/bid/9674
Reference: XF:yabb-post-sql-injection(15224)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15224
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(2) Wall, Cox
Name: CVE-2004-0292
Description:
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4
allows remote attackers to cause a denial of service
(crash) and possibly execute arbitrary code via a long
HTTP GET request.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 KarjaSoft Sami HTTP
Server 1.0.4 Buffer Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703630913205&w=2
Reference:
MISC:http://www.security-protocols.com/modules.php?name=News&file=article&sid=1746
Reference: BID:9679
Reference:
URL:http://www.securityfocus.com/bid/9679
Reference: XF:sami-http-get-bo(15237)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15237
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0293
Description:
Directory traversal vulnerability in ShopCartCGI 2.3
allows remote attackers to retrieve arbitrary files via
a .. (dot dot) in a HTTP request to (1) gotopage.cgi or
(2) genindexpage.cgi.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 ZH2004-06SA (security
advisory): ShopCartCGI v2.3 Remote
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703602707450&w=2
Reference:
MISC:http://www.zone-h.org/en/advisories/read/id=3962/
Reference:
XF:shopcartcgi-dotdot-directory-traversal(14982)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/14982
Reference: BID:9670
Reference:
URL:http://www.securityfocus.com/bid/9670
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0294
Description:
YaBB 1 SP 1.3.1 displays different error messages when a
user exists or not, which makes it easier for remote
attackers to identify valid users and conduct a brute
force password guessing attack.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 YABB information
leakage on failed login
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703591314745&w=2
Reference: BID:9677
Reference:
URL:http://www.securityfocus.com/bid/9677
Reference:
XF:yabb-invalidmessage-obtain-information(15236)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15236
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0295
Description:
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote
attackers to cause a denial of service (CPU consumption)
via an open idle connection.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 Broker FTP DoS
(Message Server)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107705346817241&w=2
Reference:
MISC:http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html
Reference: XF:broker-ftp-tsftpsrv-dos(15242)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15242
Reference: BID:9680
Reference:
URL:http://www.securityfocus.com/bid/9680
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0296
Description:
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote
attackers to cause a TsFtpSrv.exe to exit with an
exception by opening and immediately closing a
connection.
Status: Candidate
Phase: Modified (20050707)
Reference: BUGTRAQ:20040217 Broker FTP DoS
(Message Server)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107705346817241&w=2
Reference:
MISC:http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html
Reference: XF:broker-ftp-dos(15241)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15241
Reference: BID:9680
Reference:
URL:http://www.securityfocus.com/bid/9680
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
REVIEWING(1) Christey
Voter Comments:
Christey> The description is incomplete. Wonder what it was about the
original researcher that was important enough to note?
Christey> What was I saying in the desc about the original researcher???
Name: CVE-2004-0298
Description:
CesarFTP 0.99e allows remote attackers to cause a denial
of service (CPU consumption) via a long RETR parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 CesarFTP 0.99 : 100%
employment of computer resources
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712057628250&w=2
Reference: BID:9666
Reference:
URL:http://www.securityfocus.com/bid/9666
Reference: XF:cesarftp-userpass-dos(15252)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15252
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0299
Description:
Buffer overflow in smallftpd 0.99 allows local users to
cause a denial of service (crash) via an FTP request
with a large number of "/" (slash) characters.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 Smallftpd 1.0.3 DoS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107714207708375&w=2
Reference: BID:9684
Reference:
URL:http://www.securityfocus.com/bid/9684
Reference: XF:smallftpd-forwardslash-dos(15262)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15262
Votes:
NOOP(4) Wall, Cole, Armstrong, Cox
Name: CVE-2004-0300
Description:
SQL injection vulnerability in Online Store Kit 3.0
allows remote attackers to inject arbitrary SQL and gain
unauthorized access via (1) the cat parameter in
shop.php, (2) the id parameter in more.php, (3) the
cat_manufacturer parameter in shop_by_brand.php, or (4)
the id parameter in listing.php.
Status: Candidate
Phase: Modified (20051204)
Reference: BUGTRAQ:20040218 ZH2004-07SA (security
advisory): Multiple Sql injection
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712117913185&w=2
Reference:
MISC:http://www.zone-h.org/en/advisories/read/id=3972/
Reference:
MISC:http://www.systemsecure.org/advisories/ssadvisory16022004.php
Reference: OSVDB:3973
Reference: URL:http://www.osvdb.org/3973
Reference: SECTRACK:1009092
Reference:
URL:http://securitytracker.com/alerts/2004/Feb/1009092.html
Reference: SECUNIA:10902
Reference:
URL:http://secunia.com/advisories/10902/
Reference:
XF:onlinestorekit-more-sql-injection(15232)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15232
Reference: BID:9676
Reference:
URL:http://www.securityfocus.com/bid/9676
Reference: BID:9687
Reference:
URL:http://www.securityfocus.com/bid/9687
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0301
Description:
Cross-site scripting (XSS) vulnerability in more.php for
Online Store Kit 3.0 allows remote attackers to inject
arbitrary HTML via the id parameter.
Status: Candidate
Phase: Modified (20051204)
Reference:
MISC:http://www.systemsecure.org/advisories/ssadvisory16022004.php
Reference: BID:9676
Reference:
URL:http://www.securityfocus.com/bid/9676
Reference: SECTRACK:1009079
Reference:
URL:http://securitytracker.com/alerts/2004/Feb/1009079.html
Reference: SECUNIA:10902
Reference:
URL:http://secunia.com/advisories/10902/
Reference: XF:onlinestorekit-more-xss(15235)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15235
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0302
Description:
Directory traversal vulnerability in OWLS 1.0 allows
remote attackers to read arbitrary files via a .. (dot
dot) in the (1) file parameter in index.php, (2)
editfile in glossary.php, or (3) editfile in
newmultiplechoice.php.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 ZH2004-08SA (security
advisory): OWLS 1.0 Remote arbitrary files
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712123305706&w=2
Reference:
MISC:http://www.zone-h.org/en/advisories/read/id=3973/
Reference: XF:owls-file-retrieval(15249)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15249
Reference: BID:9689
Reference:
URL:http://www.securityfocus.com/bid/9689
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0303
Description:
OWLS 1.0 allows remote attackers to retrieve arbitrary
files via absolute pathnames in (1) the file parameter
in /glossaries/index.php, (2) the filename parameter in
/readings/index.php, or (3) the filename parameter in
/multiplechoice/resultsignore.php, as demonstrated using
/etc/passwd.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 ZH2004-08SA (security
advisory): OWLS 1.0 Remote arbitrary files
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712123305706&w=2
Reference:
MISC:http://www.zone-h.org/en/advisories/read/id=3973/
Reference: XF:owls-file-retrieval(15249)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15249
Reference: BID:9689
Reference:
URL:http://www.securityfocus.com/bid/9689
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0304
Description:
SQL injection vulnerability in browse_items.asp in
WebCortex WebStores 2000 6.0 allows remote attackers to
gain unauthorized access and execute arbitrary commands
via the Search_Text parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 WebCortex
Webstores2000 version 6.0 multiple security
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712159425226&w=2
Reference:
MISC:http://www.s-quadra.com/advisories/Adv-20040218.txt
Reference:
XF:webstores-browseitems-sql-injection(15253)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15253
Reference: BID:7766
Reference:
URL:http://www.securityfocus.com/bid/7766
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0305
Description:
Cross-site scripting (XSS) vulnerability in error.asp in
WebCortex WebStores 2000 6.0 allows remote attackers to
execute arbitrary script as other users and steal
session IDs via the Message_id parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 WebCortex
Webstores2000 version 6.0 multiple security
vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712159425226&w=2
Reference: XF:webstores-error-xss(15254)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15254
Reference: BID:9693
Reference:
URL:http://www.securityfocus.com/bid/9693
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0308
Description:
Unknown vulnerability in Cisco ONS 15327 before 4.1(3),
ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and
Cisco ONS15600 before 1.3(0) allows a superuser whose
account is locked out, disabled, or suspended to gain
unauthorized access via a Telnet connection to the
VxWorks shell.
Status: Candidate
Phase: Modified (20040820)
Reference: CISCO:20040219 Cisco ONS 15327, ONS
15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml
Reference: XF:cisco-ons-gain-access(15266)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15266
Reference: BID:9699
Reference:
URL:http://www.securityfocus.com/bid/9699
Reference: OSVDB:4010
Reference: URL:http://www.osvdb.org/4010
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
NOOP(1) Cox
Name: CVE-2004-0310
Description:
Cross-site scripting (XSS) vulnerability in LiveJournal
1.0 and 1.1 allows remote attackers to execute
Javascript as other users via the stylesheet, which does
not strip the semicolon or parentheses, as demonstrated
using a background:url.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040219 LiveJournal XSS
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107722627800820&w=2
Reference: BID:9700
Reference:
URL:http://www.securityfocus.com/bid/9700
Reference: XF:livejournal-url-xss(15268)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15268
Votes:
NOOP(5) Cox, Christey, Wall, Cole, Armstrong
Voter Comments:
Christey> Despite the description, the specific affected versions are
not actually known. Either they need to be removed or we need
some source that can confirm the affected versions.
Name: CVE-2004-0311
Description:
American Power Conversion (APC) Web/SNMP Management
SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped
with a default password of TENmanUFactOryPOWER, which
allows remote attackers to gain unauthorized access.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 APC 9606 SmartSlot
Web/SNMP management card "backdoor"
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703696631367&w=2
Reference: BUGTRAQ:20040219 Re: Fw: APC 9606
SmartSlot Web/SNMP management card "backdoor"
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107721020803565&w=2
Reference:
CONFIRM:http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&p_created=1077139129
Reference:
XF:apc-smartslot-default-password(15238)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15238
Reference: BID:9681
Reference:
URL:http://www.securityfocus.com/bid/9681
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Cox, Wall
Name: CVE-2004-0312
Description:
Linksys WAP55AG 1.07 allows remote attackers with access
to an SNMP read only community string to gain access to
read/write communtiy strings via a query for OID
1.3.6.1.4.1.3955.2.1.13.1.2.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 SNMP community string
disclosure in Linksys WAP55AG
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712101324233&w=2
Reference: BUGTRAQ:20040219 Re: SNMP community
string disclosure in Linksys WAP55AG
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107730681012131&w=2
Reference:
XF:linksys-snmp-strings-disclosure(15257)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15257
Reference: BID:9688
Reference:
URL:http://www.securityfocus.com/bid/9688
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0313
Description:
Buffer overflow in PSOProxy 0.91 allows remote attackers
to cause a denial of service and possibly execute
arbitrary code via a long HTTP request, as demonstrated
using a long (1) GET argument or (2) method name.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040220 Remote Buffer
Overflow in PSOProxy 0.91
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107730731900261&w=2
Reference: BID:9706
Reference:
URL:http://www.securityfocus.com/bid/9706
Reference: XF:psoproxy-long-get-bo(15275)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15275
Votes:
ACCEPT(1) Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0314
Description:
Cross-site scripting (XSS) vulnerability in done.jsp in
WebzEdit 1.9 and earlier allows remote attackers to
execute arbitrary script as other users via the message
parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040221 Cross Site Scripting
in WebzEdit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107757029514146&w=2
Reference: XF:webzedit-done-xss(15289)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15289
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0315
Description:
Buffer overflow in Avirt Voice 4.0 allows remote
attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a long GET request
on port 1080.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Remote Buffer
Overflow in Avirt Voice 4.0
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756584609841&w=2
Reference: XF:avirt-voice-get-bo(15288)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15288
Reference: BID:9721
Reference:
URL:http://www.securityfocus.com/bid/9721
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0316
Description:
Buffer overflow in Avirt Soho 4.3 allows remote
attackers to cause a denial of service (crash) via (1) a
large GET request to port 1080 or (2) a large GET
request of % characters to port 8080.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20030223 Multiple Remote
Buffer Overflow in Avirt Soho 4.3
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756666701194&w=2
Reference: XF:avirt-soho-multiple-bo(15286)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15286
Reference: BID:9722
Reference:
URL:http://www.securityfocus.com/bid/9722
Reference: BID:9723
Reference:
URL:http://www.securityfocus.com/bid/9723
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0317
Description:
Buffer overflow in eauth in Load Sharing Facility 4.x,
5.x, and 6.x allows local users or remote attackers
within the LSF cluster to cause a denial of service
(segmentation fault) and possibly execute arbitrary code
via a long LSF_From_PC parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Lam3rZ Security
Advisory #1/2004: LSF eauth vulnerability leads to
remote code execution
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756611501236&w=2
Reference: XF:lsf-eauth-execute-code(15282)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15282
Reference: BID:9719
Reference:
URL:http://www.securityfocus.com/bid/9719
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0318
Description:
Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the
LSF_EAUTH_UID environment variable, if it exists,
instead of the real UID of the user, which could allow
remote attackers within the local cluster to gain
privileges.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Lam3rZ Security
Advisory #2/2004: LSF eauth vulnerability leads to a
possibility of controlling cluster jobs on behalf of
other users
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756600403557&w=2
Reference: XF:lsf-eauth-process-hijack(15278)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15278
Reference: BID:9724
Reference:
URL:http://www.securityfocus.com/bid/9724
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0319
Description:
Cross-site scripting (XSS) vulnerability in the font tag
in ezBoard 7.3u allows remote attackers to execute
arbitrary script as other users, as demonstrated using
the background:url in a (1) font color or (2) font face
argument.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 ezBoard Cross Site
Scripting Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756639427140&w=2
Reference: XF:ezboard-font-xss(15287)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15287
Reference: BID:9725
Reference:
URL:http://www.securityfocus.com/bid/9725
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(3) Cox, Balinsky, Wall
Name: CVE-2004-0321
Description:
Team Factor 1.25 and earlier allows remote attackers to
cause a denial of service (crash) via a packet that uses
a negative number to specify the size of the data block
that follows, which causes Team Factor to read
unallocated memory.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Remote server crash
in Team Factor <= 1.25
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756001412888&w=2
Reference:
MISC:http://www.zone-h.org/advisories/read/id=4006
Reference: BID:9708
Reference:
URL:http://www.securityfocus.com/bid/9708
Reference: XF:teamfactor-packet-dos(15274)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15274
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0322
Description:
Multiple cross-site scripting (XSS) vulnerabilities in
XMB 1.8 Final SP2 allow remote attackers to execute
arbitrary script as other users via the (1) member
parameter in member.php, (2) uid parameter in
u2uadmin.php, (3) user parameter in editprofile.php, (4)
an onmouseover event in an align tag when bbcode is
allowed, or (5) img tag where bbcode is allowed.
Status: Candidate
Phase: Modified (20050718)
Reference: BUGTRAQ:20040223 [waraxe-2004-SA#004]
- Multiple vulnerabilities in XMB 1.8 Partagium Final
SP2
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756526625179&w=2
Reference: BUGTRAQ:20040225 Re:
[waraxe-2004-SA#004] - Multiple vulnerabilities in XMB
1.8 Partagium Final SP2
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html
Reference:
CONFIRM:http://www.xmbforum.com/community/boards/viewthread.php?tid=746859
Reference: BID:9726
Reference:
URL:http://www.securityfocus.com/bid/9726
Reference: XF:xmb-multiple-scripts-xss(15292)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15292
Reference: XF:xmb-bbcode-execute-code(15294)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15294
Votes:
ACCEPT(1) Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0323
Description:
Multiple SQL injection vulnerabilities in XMB 1.8 Final
SP2 allow remote attackers to inject arbitrary SQL and
gain privileges via the (1) ppp parameter in
viewthread.php, (2) desc parameter in misc.php, (3) tpp
parameter in forumdisplay.php, (4) ascdesc parameter in
forumdisplay.php, or (5) the addon parameter in
stats.php. NOTE: it has also been shown that item (3) is
also in XMB 1.9 beta.
Status: Candidate
Phase: Modified (20051128)
Reference: BUGTRAQ:20040223 [waraxe-2004-SA#004]
- Multiple vulnerabilities in XMB 1.8 Partagium Final
SP2
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756526625179&w=2
Reference: BUGTRAQ:20040225 Re:
[waraxe-2004-SA#004] - Multiple vulnerabilities in XMB
1.8 Partagium Final SP2
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html
Reference: BUGTRAQ:20040326 [waraxe-2004-SA#012 -
Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9
beta]
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html
Reference:
CONFIRM:http://www.xmbforum.com/community/boards/viewthread.php?tid=746859
Reference: BID:9726
Reference:
URL:http://www.securityfocus.com/bid/9726
Reference: XF:xmb-multiple-sql-injection(15295)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15295
Votes:
ACCEPT(1) Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0324
Description:
Confirm 0.62 and earlier could allow remote attackers to
execute arbitrary code via an e-mail header that
contains shell metacharacters such as ", `, |, ;, or $.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Lam3rZ Security
Advisory #3/2004: A bug in Confirm leads to remote
command execution
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107757320401858&w=2
Reference: XF:confirm-header-gain-access(15290)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15290
Reference: BID:9728
Reference:
URL:http://www.securityfocus.com/bid/9728
Votes:
ACCEPT(1) Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0325
Description:
TYPSoft FTP Server 1.10 allows remote authenticated
users to cause a denial of service (CPU consumption) via
"//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4)
size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto,
(10) rmd, or (11) xrmd, as demonstrated using
"//../qwerty".
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 TYPSoft FTP Server
1.10 multiple vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107764173821905&w=2
Reference: BID:9702
Reference:
URL:http://www.securityfocus.com/bid/9702
Reference: XF:typsoft-ftp-command-dos(15306)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15306
Votes:
ACCEPT(1) Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0326
Description:
Buffer overflow in the web proxy for GateKeeper Pro 4.7
allows remote attackers to execute arbitrary code via a
long GET request.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040222 GateKeeper Pro 4.7
buffer overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107755692400728&w=2
Reference: FULLDISC:20040222 GateKeeper Pro 4.7
buffer overflow
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017703.html
Reference: BID:9716
Reference:
URL:http://www.securityfocus.com/bid/9716
Reference: XF:gatekeeper-long-get-bo(15277)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15277
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(3) Cox, Balinsky, Wall
Name: CVE-2004-0327
Description:
Directory traversal vulnerability in functions.php in
PhpNewsManager 1.46 allows remote attackers to retrieve
arbitrary files via .. (dot dot) sequences in the clang
parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 ZH2004-09SA (security
advisory): PhpNewsManager Remote arbitrary
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107772470111000&w=2
Reference:
MISC:http://www.zone-h.org/advisories/read/id=4024
Reference:
XF:phpnewsmanager-dotdot-directory-traversal(15283)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15283
Reference: BID:9720
Reference:
URL:http://www.securityfocus.com/bid/9720
Votes:
ACCEPT(1) Cole
NOOP(4) Cox, Balinsky, Wall, Armstrong
Name: CVE-2004-0328
Description:
Gigabyte Gn-B46B 2.4Ghz wireless broadband router
firmware 1.003.00 allows local users on the same local
network as the router to bypass authentication by using
a copy of the router's html menu on a separate system.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040224 Gigabyte Broadband
Router - Multiple Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107766719227942&w=2
Reference: BID:9740
Reference:
URL:http://www.securityfocus.com/bid/9740
Reference:
XF:gigabyte-gnb46b-bypass-authentication(15313)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15313
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0329
Description:
FreeChat 1.1.1a allows remote attackers to cause a
denial of service (crash) via certain unexpected
strings, as demonstrated using "aaaaa".
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 Denial Of Service in
FreeChat 1.1.1a
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107781043621074&w=2
Reference: XF:freechat-string-dos(15321)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15321
Reference: BID:9744
Reference:
URL:http://www.securityfocus.com/bid/9744
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0330
Description:
Buffer overflow in Serv-U ftp before 5.0.0.4 allows
remote authenticated users to execute arbitrary code via
a long time zone argument to the MDTM command.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 [vulnwatch] Serv-U
MDTM Command Buffer Overflow Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107781164214399&w=2
Reference:
MISC:http://www.cnhonker.com/advisory/serv-u.mdtm.txt
Reference: XF:servu-mdtm-bo(15323)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15323
Reference: BID:9751
Reference:
URL:http://www.securityfocus.com/bid/9751
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0331
Description:
Heap-based buffer overflow in Dell OpenManage Web Server
3.4.0 allows remote attackers to cause a denial of
service (crash) via a HTTP POST with a long application
variable.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 Dell OpenManage Web
Server Heap Overflow (Pre-Auth)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107781539829143&w=2
Reference:
MISC:http://sh0dan.org/files/domadv.txt
Reference:
XF:dell-openmanage-ocsgetoeminpathfile-bo(15325)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15325
Reference: BID:9750
Reference:
URL:http://www.securityfocus.com/bid/9750
Votes:
ACCEPT(1) Cole
NOOP(3) Cox, Wall, Armstrong
Name: CVE-2004-0332
Description:
Extremail 1.5.9 does not check passwords correctly when
they are all digits or begin with a digit, which allows
remote attackers to gain privileges.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 Extremail Security
Problem
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107783767517850&w=2
Reference:
XF:extremail-password-gain-access(15329)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15329
Reference: BID:9754
Reference:
URL:http://www.securityfocus.com/bid/9754
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0333
Description:
Buffer overflow in the UUDeview package, as used in
WinZip 6.2 through WinZip 8.1 SR-1, and possibly other
packages, allows remote attackers to execute arbitrary
code via a MIME archive with certain long MIME
parameters.
Status: Candidate
Phase: Modified (20050808)
Reference: IDEFENSE:20040227 WinZip MIME Parsing
Buffer Overflow Vulnerability
Reference:
URL:http://www.idefense.com/application/poi/display?id=76&type=vulnerabiliti&flashstatus=true
Reference:
CONFIRM:http://www.winzip.com/fmwz90.htm
Reference:
CONFIRM:http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html
Reference: CERT-VN:VU#116182
Reference:
URL:http://www.kb.cert.org/vuls/id/116182
Reference: CIAC:O-092
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-092.shtml
Reference: BID:9758
Reference:
URL:http://www.securityfocus.com/bid/9758
Reference: OSVDB:4119
Reference: URL:http://www.osvdb.org/4119
Reference: SECUNIA:10995
Reference:
URL:http://secunia.com/advisories/10995
Reference: SECUNIA:11019
Reference:
URL:http://secunia.com/advisories/11019
Reference: XF:uudeview-multiple-bo(15490)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15490
Reference: XF:winzip-mime-bo(15336)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15336
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
NOOP(2) Cox, Christey
Voter Comments:
Christey> Consider this Gentoo reference:
BUGTRAQ:20040328 [ GLSA 200403-05 ] UUDeview MIME Buffer Overflow
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108057738810928&w=2
May need to rephrase this description to emphasize UUDeview
over WinZip.
Name: CVE-2004-0334
Description:
InnoMedia VideoPhone allows remote attackers to bypass
Basic Authorization via an HTTP request to (1)
videophone_admindetail.asp, (2) videophone_syscfg.asp,
(3) videophone_upgrade.asp, or (4)
videophone_sysctrl.asp that contains a trailing /
(slash). NOTE: the original report mentioned AXIS 2100
Network Camera, but this was likely a cut-and-paste
error.
Status: Candidate
Phase: Modified (20060816)
Reference: BUGTRAQ:20040227 InnoMedia VideoPhone
Authorization Bypass
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799556111784&w=2
Reference: OSVDB:4809
Reference: URL:http://www.osvdb.org/4809
Reference: SECTRACK:1009522
Reference:
URL:http://securitytracker.com/alerts/2004/Mar/1009522.html
Reference:
XF:InnoMedia-videophone-bypass-authentication(15636)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15636
Votes:
NOOP(5) Cox, Christey, Wall, Cole, Armstrong
Voter Comments:
Christey> According to SecurityTracker.com, the initial advisory
erroneously mentions Axis 1200:
MISC:http://securitytracker.com/alerts/2004/Mar/1009522.html
Name: CVE-2004-0335
Description:
LAN SUITE Web Mail 602Pro, when configured to use the
"Directory browsing" feature, allows remote attackers to
obtain a directory listing via an HTTP request to (1)
index.html, (2) cgi-bin/, or (3) users/.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 LAN SUITE Web Mail
602Pro Multiple Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799540630302&w=2
Reference: BUGTRAQ:20040310 Re: LAN SUITE Web
Mail 602Pro Multiple Vulnerabilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html
Reference: XF:602pro-directory-listing(15349)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15349
Reference: BID:9780
Reference:
URL:http://www.securityfocus.com/bid/9780
Votes:
ACCEPT(1) Cole
NOOP(2) Cox, Wall
REJECT(1) Armstrong
Voter Comments:
Armstrong> If this is a design feature - then it should not be classed as a vulnerability.
Name: CVE-2004-0337
Description:
Cross-site scripting (XSS) vulnerability in LAN SUITE
Web Mail 602Pro allows remote attackers to execute
arbitrary script or HTML as other users via a URL to
index.html, followed by a / (slash) and the desired
script. NOTE: the vendor states that this bug could not
be reproduced, so this issue may be REJECTed in the
future.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 LAN SUITE Web Mail
602Pro Multiple Vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799540630302&w=2
Reference: BUGTRAQ:20040310 Re: LAN SUITE Web
Mail 602Pro Multiple Vulnerabilities
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html
Reference: XF:602pro-index-xss(15351)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15351
Reference: BID:9777
Reference:
URL:http://www.securityfocus.com/bid/9777
Votes:
ACCEPT(1) Cole
NOOP(3) Cox, Wall, Armstrong
Name: CVE-2004-0338
Description:
SQL injection vulnerability in search.php for Invision
Board Forum allows remote attackers to execute arbitrary
SQL queries via the st parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 Invision Power Board
SQL injection!
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799527428834&w=2
Reference:
XF:invision-search-sql-injection(15343)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15343
Reference: BID:9766
Reference:
URL:http://www.securityfocus.com/bid/9766
Votes:
ACCEPT(1) Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0339
Description:
Cross-site scripting (XSS) vulnerability in
ViewTopic.php in phpBB, possibly 2.0.6c and earlier,
allows remote attackers to execute arbitrary script or
HTML as other users via the postorder parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 New phpBB
ViewTopic.php Cross Site Scripting Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799508130700&w=2
Reference: XF:phpbb-viewtopicphp-xss(15348)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15348
Reference: BID:9765
Reference:
URL:http://www.securityfocus.com/bid/9765
Votes:
ACCEPT(1) Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0340
Description:
Stack-based buffer overflow in WFTPD Pro Server 3.21
Release 1, Pro Server 3.20 Release 2, Server 3.21
Release 1, and Server 3.10 allows local users to execute
arbitrary code via long (1) LIST, (2) NLST, or (3) STAT
commands.
Status: Candidate
Phase: Modified (20050719)
Reference: BUGTRAQ:20040228 Critical WFTPD buffer
overflow vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107801208004699&w=2
Reference: BID:9767
Reference:
URL:http://www.securityfocus.com/bid/9767
Reference: SECUNIA:11001
Reference:
URL:http://secunia.com/advisories/11001
Reference: XF:wftpd-ftp-commands-bo(15340)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15340
Votes:
ACCEPT(2) Wall, Armstrong
NOOP(2) Cox, Cole
Name: CVE-2004-0341
Description:
WFTPD Pro Server 3.21 Release 1 allocates memory for a
command until a 0Ah byte (newline) is sent, which allows
local users to cause a denial of service (CPU
consumption) by continuing to send a long command that
does not contain a newline.
Status: Candidate
Phase: Modified (20050719)
Reference: BUGTRAQ:20040228 Multiple WFTPD Denial
of Service vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107801142924976&w=2
Reference: BID:9767
Reference:
URL:http://www.securityfocus.com/bid/9767
Reference: OSVDB:4115
Reference: URL:http://www.osvdb.org/4115
Reference: SECUNIA:11001
Reference:
URL:http://secunia.com/advisories/11001
Reference: XF:wftpd-string-0Ahbyte-dos(15341)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15341
Votes:
ACCEPT(2) Wall, Armstrong
NOOP(2) Cox, Cole
Name: CVE-2004-0342
Description:
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech
option enabled, allows local users to cause a denial of
service (crash) via a (1) MKD or (2) XMKD command that
causes an absolute path of 260 characters to be used,
which overwrites a cookie with a null character,
possibly due to an off-by-one error.
Status: Candidate
Phase: Modified (20050718)
Reference: BUGTRAQ:20040228 Multiple WFTPD Denial
of Service vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107801142924976&w=2
Reference: BID:9767
Reference:
URL:http://www.securityfocus.com/bid/9767
Reference: OSVDB:4116
Reference: URL:http://www.osvdb.org/4116
Reference: SECUNIA:11001
Reference:
URL:http://secunia.com/advisories/11001
Reference: XF:wftpd-ftp-command-dos(15342)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15342
Votes:
ACCEPT(2) Wall, Armstrong
NOOP(2) Cox, Cole
Name: CVE-2004-0343
Description:
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4
through 1.5.5b allow remote attackers to execute
arbitrary SQL via (1) the msg parameter in
ModifyMessage.php or (2) the postid parameter in
ModifyMessage.php.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040301 YabbSE (3 on 1)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107816202813083&w=2
Reference: XF:yabb-multiple-sql-injection(15354)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15354
Reference: BID:9774
Reference:
URL:http://www.securityfocus.com/bid/9774
Votes:
ACCEPT(3) Stracener, Cole, Armstrong
NOOP(3) Cox, Balinsky, Wall
REVIEWING(1) Green
Name: CVE-2004-0344
Description:
Directory traversal vulnerability in ModifyMessage.php
in YaBB SE 1.5.4 through 1.5.5b allows remote attackers
to delete arbitrary files via a .. (dot dot) in the
attachOld parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040301 YabbSE (3 on 1)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107816202813083&w=2
Reference: BID:9774
Reference:
URL:http://www.securityfocus.com/bid/9774
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0345
Description:
Buffer overflow in Red Faction client 1.20 and earlier
allows remote servers to execute arbitrary code via a
long server name.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040301 Clients broadcast
buffer overflow in Red Faction <= 1.20
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107816217901923&w=2
Reference: XF:redfaction-bo(15353)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15353
Reference: BID:9775
Reference:
URL:http://www.securityfocus.com/bid/9775
Votes:
ACCEPT(1) Stracener
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0346
Description:
Off-by-one buffer overflow in _xlate_ascii_write() in
ProFTPD 1.2.7 through 1.2.9rc2p allows local users to
gain privileges via a 1024 byte RETR command.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040302 The Cult of a
Cardinal Number
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107824679817240&w=2
Reference: XF:proftpd-offbyone-bo(15387)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15387
Reference: BID:9782
Reference:
URL:http://www.securityfocus.com/bid/9782
Votes:
ACCEPT(2) Stracener, Armstrong
NOOP(3) Cox, Wall, Cole
Name: CVE-2004-0348
Description:
SQL injection vulnerability in viewCart.asp in
SpiderSales shopping cart software allows remote
attackers to execute arbitrary SQL via the userId
parameter.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 Spider Sales shopping
cart software multiple security vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833097705486&w=2
Reference:
MISC:http://www.s-quadra.com/advisories/Adv-20040303.txt
Reference:
XF:spidersales-userid-sql-injection(15371)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15371
Reference: BID:9799
Reference:
URL:http://www.securityfocus.com/bid/9799
Votes:
ACCEPT(1) Cole
NOOP(3) Cox, Wall, Armstrong
Name: CVE-2004-0349
Description:
Directory traversal vulnerability in GWeb HTTP Server
0.6 allows remote attackers to view arbitrary files via
a .. (dot dot) in the URL.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 directory traversal
in GWeb 0.6
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833161617397&w=2
Reference:
XF:gweb-dotdot-directory-traversal(15381)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15381
Reference: BID:9742
Reference:
URL:http://www.securityfocus.com/bid/9742
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0350
Description:
SpiderSales shopping cart does not enforce a minimum
length for the private key, which can make it easier for
local users to obtain the private key by factoring.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 Spider Sales shopping
cart software multiple security vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833097705486&w=2
Reference: FULLDISC:20040303 Spider Sales
shopping cart software multiple security vulnerabilities
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html
Reference:
MISC:http://www.s-quadra.com/advisories/Adv-20040303.txt
Reference: XF:spidersales-weak-encryption(15370)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15370
Reference: BID:9799
Reference:
URL:http://www.securityfocus.com/bid/9799
Votes:
ACCEPT(1) Cole
NOOP(3) Cox, Wall, Armstrong
Name: CVE-2004-0351
Description:
Spider Sales shopping cart stores the private key in the
same database and table as the public key, which allows
local users with access to the database to decrypt data.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 Spider Sales shopping
cart software multiple security vulnerabilities
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833097705486&w=2
Reference: FULLDISC:20040303 Spider Sales
shopping cart software multiple security vulnerabilities
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html
Reference: XF:spidersales-weak-encryption(15370)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15370
Reference: BID:9799
Reference:
URL:http://www.securityfocus.com/bid/9799
Votes:
ACCEPT(1) Cole
NOOP(3) Cox, Wall, Armstrong
Name: CVE-2004-0352
Description:
Cisco 11000 Series Content Services Switches (CSS)
running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x)
before 06.10(02.05)S allow remote attackers to cause a
denial of service (device reset) via a malformed packet
to UDP port 5002.
Status: Candidate
Phase: Proposed (20040318)
Reference: CISCO:20040304 Cisco CSS 11000 Series
Content Services Switches Malformed UDP Packet
Vulnerability
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040304-css.shtml
Reference: CERT-VN:VU#363374
Reference:
URL:http://www.kb.cert.org/vuls/id/363374
Reference: XF:cisco-css-udp-dos(15388)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15388
Reference: BID:9806
Reference:
URL:http://www.securityfocus.com/bid/9806
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
NOOP(2) Cox, Christey
Voter Comments:
Christey> According to the Details section of the advisory, the
vulnerability can only be exploited through the management port, which
is "available solely through the physical management interface." So,
change the description to point out that physical access is required.
Thanks to esCERT-UPC for pointing this out.
Name: CVE-2004-0353
Description:
Multiple buffer overflows in auth_ident() function in
auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and
3.9.93 allow remote attackers to gain privileges via a
long string.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040304 GNU Anubis buffer
overflows and format string bugs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107843915424588&w=2
Reference: MLIST:[bug-anubis] 20040228 Important
security update
Reference:
URL:http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html
Reference: BUGTRAQ:20040310 GNU Anubis 3.6.2
remote root exploit
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107894315012081&w=2
Reference: BID:9772
Reference:
URL:http://www.securityfocus.com/bid/9772
Reference: XF:anubis-ident-bo(15345)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15345
Votes:
ACCEPT(4) Green, Baker, Cole, Armstrong
NOOP(2) Cox, Wall
Voter Comments:
Green> VERIFIED-BY-SOMEONE-I-TRUST
Name: CVE-2004-0354
Description:
Multiple format string vulnerabilities in GNU Anubis
3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote
attackers to execute arbitrary code via format string
specifiers in strings passed to (1) the info function in
log.c, (2) the anubis_error function in errs.c, or (3)
the ssl_error function in ssl.c.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040304 GNU Anubis buffer
overflows and format string bugs
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107843915424588&w=2
Reference: MLIST:[bug-anubis] 20040228 Important
security update
Reference:
URL:http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html
Reference: BID:9772
Reference:
URL:http://www.securityfocus.com/bid/9772
Reference: XF:anubis-format-string(15346)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15346
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Cox, Wall
Name: CVE-2004-0355
Description:
Invision Power Board 1.3 Final allows remote attackers
to gain sensitive information by selecting a file for
"Personal Photo" that is not an image file, which
displays the installation path in an error message.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040305 Invision Power Board
1.3 Final Path Disclosure Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107850510428567&w=2
Reference:
XF:invision-invalid-path-disclosure(15400)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15400
Reference: BID:9810
Reference:
URL:http://www.securityfocus.com/bid/9810
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0357
Description:
Stack-based buffer overflows in SL Mail Pro 2.0.9 allow
remote attackers to execute arbitrary code via (1)
user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040305 SLWebMail Multiple
Buffer Overflow Vulnerabilities (#NISR05022004b)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107850432827699&w=2
Reference:
CONFIRM:http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf
Reference:
MISC:http://www.nextgenss.com/advisories/slmailwm.txt
Reference: XF:slmail-slwebmail-bo(15399)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15399
Reference: BID:9808
Reference:
URL:http://www.securityfocus.com/bid/9808
Votes:
ACCEPT(3) Baker, Cole, Armstrong
NOOP(2) Cox, Wall
Name: CVE-2004-0358
Description:
Cross-site scripting (XSS) vulnerability in VirtuaNews
Admin Panel Pro 1.0.3 allows remote attackers to execute
arbitrary script as other users via (1) the mainnews
parameter in admin.php, (2) the expand parameter in
admin.php, (3) the id parameter in admin.php, (4) the
catid parameter in admin.php, or (5) an unnamed
parameter during the newslogo_upload action in
admin.php.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040305 VirtuaNews Admin
Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107851556116088&w=2
Reference: BUGTRAQ:20040307 RE: VirtuaNews Admin
Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity
Reference:
URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0069.html
Reference: XF:virtuanews-multiple-xss(15402)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15402
Reference: BID:9812
Reference:
URL:http://www.securityfocus.com/bid/9812
Reference: BID:9819
Reference:
URL:http://www.securityfocus.com/bid/9819
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0359
Description:
Cross-site scripting (XSS) vulnerability in index.php
for Invision Power Board 1.3 final allows remote
attackers to execute arbitrary script as other users via
the (1) c, (2) f, (3) showtopic, (4) showuser, or (5)
username parameters.
Status: Candidate
Phase: Modified (20050719)
Reference: BUGTRAQ:20040305 Invision Power Board
v1.3 Final Cross Site Scripting Vulnerabillity
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107851589701916&w=2
Reference: BID:9768
Reference:
URL:http://www.securityfocus.com/bid/9768
Reference: OSVDB:4154
Reference: URL:http://www.osvdb.org/4154
Reference: SECUNIA:11053
Reference:
URL:http://secunia.com/advisories/11053
Reference: XF:invision-xss(15403)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15403
Votes:
NOOP(4) Cox, Wall, Cole, Armstrong
Name: CVE-2004-0360
Description:
Unknown vulnerability in passwd(1) in Solaris 8.0 and
9.0 allows local users to gain privileges via unknown
attack vectors.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:200470305 O-088: Sun passwd(1)
Command Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107852274423414&w=2
Reference: SUNALERT:57454
Reference:
URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57454
Reference: CERT-VN:VU#694782
Reference:
URL:http://www.kb.cert.org/vuls/id/694782
Reference: CIAC:O-088
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-088.shtml
Reference:
XF:solaris-passwd-gain-privileges(15327)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15327
Reference: BID:9757
Reference:
URL:http://www.securityfocus.com/bid/9757
Votes:
ACCEPT(4) Wall, Baker, Cole, Armstrong
NOOP(1) Cox
Name: CVE-2004-0361
Description:
The Javascript engine in Safari 1.2 and earlier allows
remote attackers to cause a denial of service
(segmentation fault) by creating a new Array object with
a large size value, then writing into that array.
Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040306 Safari javascript
array overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107861828510106&w=2
Reference:
MISC:http://www.insecure.ws/article.php?story=2004021918172533
Reference: BID:9815
Reference:
URL:http://www.securityfocus.com/bid/9815
Reference: XF:safari-array-dos(15413)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15413
Votes:
ACCEPT(2) Cole, Armstrong
NOOP(2) Cox, Wall
Name: CVE-2004-0362
Description:
Multiple stack-based buffer overflows in the ICQ parsing
routines of the ISS Protocol Analysis Module (PAM)
component, as used in various RealSecure, Proventia, and
BlackICE products, allow remote attackers to execute
arbitrary code via a SRV_MULTI response containing a
SRV_USER_ONLINE response packet and a SRV_META_USER
response packet with long (1) nickname, (2) firstname,
(3) lastname, or (4) email address fields, as exploited
by the Witty worm.
Status: Candidate
Phase: Assigned (20040318)
Reference: BUGTRAQ:20040318 EEYE: Internet
Security Systems PAM ICQ Server Response Processing
Vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107965651712378&w=2
Reference: EEYE:AD20040318
Reference:
URL:http://www.eeye.com/html/Research/Advisories/AD20040318.html
Reference: ISS:20040318 Vulnerability in ICQ
Parsing in ISS Products
Reference:
URL:http://xforce.iss.net/xforce/alerts/id/166
Reference: CERT-VN:VU#947254
Reference:
URL:http://www.kb.cert.org/vuls/id/947254
Reference: CIAC:O-104
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-104.shtml
Reference: BID:9913
Reference:
URL:http://www.securityfocus.com/bid/9913
Reference: OSVDB:4355
Reference: URL:http://www.osvdb.org/4355
Reference: SECUNIA:11073
Reference:
URL:http://secunia.com/advisories/11073
Reference: XF:pam-icq-parsing-bo(15442)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15442
Reference: XF:witty-worm-propagation(15543)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15543
Votes:
Name: CVE-2004-0363
Description:
Stack-based buffer overflow in the SymSpamHelper ActiveX
component (symspam.dll) in Norton AntiSpam 2004, as used
in Norton Internet Security 2004, allows remote
attackers to execute arbitrary code via a long parameter
to the LaunchCustomRuleWizard method.
Status: Candidate
Phase: Assigned (20040319)
Reference: BUGTRAQ:20040319 Norton AntiSpam
Remote Buffer Overrun (#NISR19042004a)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107970870606638&w=2
Reference:
MISC:http://www.nextgenss.com/advisories/antispam.txt
Reference: BUGTRAQ:20040319 Ref: NGSSoftware
Advisories NISR19042004a and NISR19042004b
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107980262324362&w=2
Reference:
CONFIRM:http://www.sarc.com/avcenter/security/Content/2004.03.19.html
Reference: CERT-VN:VU#344718
Reference:
URL:http://www.kb.cert.org/vuls/id/344718
Reference: BID:9916
Reference:
URL:http://www.securityfocus.com/bid/9916
Reference: SECUNIA:11169
Reference:
URL:http://secunia.com/advisories/11169
Reference:
XF:nas-launchcustomrulewizard-bo(15536)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15536
Votes:
Name: CVE-2004-0364
Description:
The WrapNISUM ActiveX component (WrapUM.dll) in Norton
Internet Security 2004 is marked safe for scripting,
which allows remote attackers to execute arbitrary
programs via the LaunchURL method.
Status: Candidate
Phase: Assigned (20040319)
Reference: BUGTRAQ:20040319 Norton Internet
Security Remote Command Execution (#NISR19042004b)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107970885922442&w=2
Reference:
MISC:http://www.nextgenss.com/advisories/nisrce.txt
Reference: BUGTRAQ:20040319 Ref: NGSSoftware
Advisories NISR19042004a and NISR19042004b
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107980262324362&w=2
Reference:
CONFIRM:http://www.sarc.com/avcenter/security/Content/2004.03.19.html
Reference: CERT-VN:VU#549054
Reference:
URL:http://www.kb.cert.org/vuls/id/549054
Reference: BID:9915
Reference:
URL:http://www.securityfocus.com/bid/9915
Reference: SECUNIA:11168
Reference:
URL:http://secunia.com/advisories/11168
Reference:
XF:norton-is-launchurl-command-execution(15538)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15538
Votes:
Name: CVE-2004-0365
Description:
The dissect_attribute_value_pairs function in
packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows
remote attackers to cause a denial of service (crash)
via a malformed RADIUS packet that triggers a null
dereference.
Status: Candidate
Phase: Assigned (20040322)
Reference: MLIST:[ethereal-dev] 20040318 ethereal
radius dissector vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=ethereal-dev&m=107962966700423&w=2
Reference:
CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00013.html
Reference: BUGTRAQ:20040329 LNSA-#2004-0007:
Multiple security problems in Ethereal
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058005324316&w=2
Reference: GENTOO:GLSA-200403-07
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-07.xml
Reference: CONECTIVA:CLA-2004:835
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
Reference: MANDRAKE:MDKSA-2004:024
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
Reference: REDHAT:RHSA-2004:136
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-136.html
Reference: REDHAT:RHSA-2004:137
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-137.html
Reference: BUGTRAQ:20040416 [OpenPKG-SA-2004.015]
OpenPKG Security Advisory (ethereal)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213710306260&w=2
Reference: CERT-VN:VU#124454
Reference:
URL:http://www.kb.cert.org/vuls/id/124454
Reference: OVAL:oval:org.mitre.oval:def:879
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:879
Reference: OVAL:oval:org.mitre.oval:def:891
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:891
Reference: SECUNIA:11185
Reference:
URL:http://secunia.com/advisories/11185
Reference: XF:ethereal-radius-dos(15571)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15571
Votes:
Name: CVE-2004-0366
Description:
SQL injection vulnerability in the libpam-pgsql library
before 0.5.2 allows attackers to execute arbitrary SQL
statements.
Status: Candidate
Phase: Assigned (20040322)
Reference: DEBIAN:DSA-469
Reference:
URL:http://www.debian.org/security/2004/dsa-469
Reference: BID:10266
Reference:
URL:http://www.securityfocus.com/bid/10266
Reference: SECUNIA:11237
Reference:
URL:http://secunia.com/advisories/11237
Reference: XF:pam-pgsql-sql-injection(15651)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15651
Votes:
Name: CVE-2004-0367
Description:
Ethereal 0.10.1 to 0.10.2 allows remote attackers to
cause a denial of service (crash) via a zero-length
Presentation protocol selector.
Status: Candidate
Phase: Assigned (20040322)
Reference:
CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00013.html
Reference: MLIST:[Ethereal-dev] 20040416 Possibly
incorrect CVE entry CAN-2004-0367
Reference:
URL:http://www.ethereal.com/lists/ethereal-dev/200404/msg00296.html
Reference: BUGTRAQ:20040329 LNSA-#2004-0007:
Multiple security problems in Ethereal
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058005324316&w=2
Reference: GENTOO:GLSA-200403-07
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-07.xml
Reference: CONECTIVA:CLA-2004:835
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
Reference: MANDRAKE:MDKSA-2004:024
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
Reference: REDHAT:RHSA-2004:136
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-136.html
Reference: REDHAT:RHSA-2004:137
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-137.html
Reference: CERT-VN:VU#792286
Reference:
URL:http://www.kb.cert.org/vuls/id/792286
Reference: OVAL:oval:org.mitre.oval:def:880
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:880
Reference: OVAL:oval:org.mitre.oval:def:905
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:905
Reference: SECUNIA:11185
Reference:
URL:http://secunia.com/advisories/11185
Reference:
XF:ethereal-zero-presentation-dos(15570)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15570
Votes:
Name: CVE-2004-0368
Description:
Double free vulnerability in dtlogin in CDE on Solaris,
HP-UX, and other operating systems allows remote
attackers to execute arbitrary code via a crafted XDMCP
packet.
Status: Candidate
Phase: Assigned (20040323)
Reference: VULNWATCH:20040323 how much fun can
you have with UDP?
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0064.html
Reference: MLIST:[Dailydave] 20040323 dtlogin
advisory
Reference:
URL:http://lists.immunitysec.com/pipermail/dailydave/2004-March/000402.html
Reference:
MISC:http://www.immunitysec.com/downloads/dtlogin.sxw.pdf
Reference: HP:HPSBUX01038
Reference:
URL:http://www.auscert.org.au/render.html?it=4103&cid=3734
Reference: SGI:20040801-01-P
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P
Reference: SUNALERT:57539
Reference:
URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57539-1&searchclause=security
Reference: SUNALERT:101478
Reference:
URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101478-1
Reference: CERT-VN:VU#179804
Reference:
URL:http://www.kb.cert.org/vuls/id/179804
Reference: CIAC:O-129
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-129.shtml
Reference: OVAL:oval:org.mitre.oval:def:1436
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1436
Reference: SECUNIA:11210
Reference:
URL:http://secunia.com/advisories/11210/
Reference: SECUNIA:11214
Reference:
URL:http://secunia.com/advisories/11214/
Reference: SECUNIA:11614
Reference:
URL:http://secunia.com/advisories/11614/
Reference: SECUNIA:11495
Reference:
URL:http://secunia.com/advisories/11495/
Reference: BID:9958
Reference:
URL:http://www.securityfocus.com/bid/9958
Reference: XF:cde-dtlogin-double-free(15581)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15581
Votes:
Name: CVE-2004-0369
Description:
Buffer overflow in Entrust LibKmp ISAKMP library, as
used by Symantec Enterprise Firewall 7.0 through 8.0,
Gateway Security 5300 1.0, Gateway Security 5400 2.0,
and VelociRaptor 1.5, allows remote attackers to execute
arbitrary code via a crafted ISAKMP payload.
Status: Candidate
Phase: Assigned (20040324)
Reference: ISS:20040826 Entrust LibKmp Library
Buffer Overflow
Reference:
URL:http://xforce.iss.net/xforce/alerts/id/181
Reference:
CONFIRM:http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html
Reference: AUSCERT:ESB-2004.0538
Reference:
URL:http://www.auscert.org.au/render.html?it=4339
Reference: CIAC:O-206
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-206.shtml
Reference: BID:11039
Reference:
URL:http://www.securityfocus.com/bid/11039
Reference: XF:isakmp-spi-size-bo(15669)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15669
Votes:
Name: CVE-2004-0370
Description:
The setsockopt call in the KAME Project IPv6
implementation, as used in FreeBSD 5.2, does not
properly handle certain IPv6 socket options, which could
allow attackers to read kernel memory and cause a system
panic.
Status: Candidate
Phase: Assigned (20040324)
Reference: FREEBSD:FreeBSD-SA-04:06
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:06.ipv6.asc
Reference: BID:9992
Reference:
URL:http://www.securityfocus.com/bid/9992
Reference: SECUNIA:11233
Reference:
URL:http://secunia.com/advisories/11233
Reference: XF:freebsd-ipv6-dos(15662)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15662
Votes:
Name: CVE-2004-0371
Description:
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does
not properly perform certain consistency checks for
cross-realm requests, which allows remote attackers with
control of a realm to impersonate others in the
cross-realm trust path.
Status: Candidate
Phase: Assigned (20040324)
Reference:
CONFIRM:http://www.pdc.kth.se/heimdal/advisory/2004-04-01/
Reference: DEBIAN:DSA-476
Reference:
URL:http://www.debian.org/security/2004/dsa-476
Reference: FREEBSD:FreeBSD-SA-04:08
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:08.heimdal.asc
Reference: OPENBSD:20040530 009: SECURITY FIX:
May 30, 2004
Reference:
URL:ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/009_kerberos.patch
Reference: GENTOO:GLSA-200404-09
Reference:
URL:http://security.gentoo.org/glsa/glsa-200404-09.xml
Reference: XF:heimdal-cross-realm-spoofing(15701)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15701
Votes:
Name: CVE-2004-0372
Description:
xine allows local users to overwrite arbitrary files via
a symlink attack on a bug report email that is generated
by the (1) xine-bugreport or (2) xine-check scripts.
Status: Candidate
Phase: Assigned (20040325)
Reference: BUGTRAQ:20040320
xine-check/xine-bugreport symlink vulnerability.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107997911025558&w=2
Reference: DEBIAN:DSA-477
Reference:
URL:http://www.debian.org/security/2004/dsa-477
Reference: GENTOO:GLSA-200404-20
Reference:
URL:http://security.gentoo.org/glsa/glsa-200404-20.xml
Reference: BID:9939
Reference:
URL:http://www.securityfocus.com/bid/9939
Reference:
XF:xine-xinebugreport-xinecheck-symlink(15564)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15564
Votes:
Name: CVE-2004-0373
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040326)
Votes:
Name: CVE-2004-0374
Description:
Interchange before 5.0.1 allows remote attackers to
"expose the content of arbitrary variables" and read or
modify sensitive SQL information via an HTTP request
ending with the "__SQLUSER__" string.
Status: Candidate
Phase: Assigned (20040329)
Reference: MLIST:[interchange-announce] 20040329
Security Problem in Interchange
Reference:
URL:http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html
Reference:
CONFIRM:http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW
Reference: DEBIAN:DSA-471
Reference:
URL:http://www.debian.org/security/2004/dsa-471
Reference: BID:10005
Reference:
URL:http://www.securityfocus.com/bid/10005
Reference: SECUNIA:11234
Reference:
URL:http://secunia.com/advisories/11234
Reference:
XF:interchange-url-obtain-information(15670)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15670
Votes:
Name: CVE-2004-0375
Description:
SYMNDIS.SYS in Symantec Norton Internet Security 2003
and 2004, Norton Personal Firewall 2003 and 2004, Client
Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1
allow remote attackers to cause a denial of service
(infinite loop) via a TCP packet with (1) SACK option or
(2) Alternate Checksum Data option followed by a length
of zero.
Status: Candidate
Phase: Assigned (20040329)
Reference: BUGTRAQ:20040423 EEYE: Symantec
Multiple Firewall TCP Options Denial of Service
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108275582432246&w=2
Reference:
MISC:http://www.eeye.com/html/Research/Upcoming/20040309.html
Reference:
CONFIRM:http://www.symantec.com/avcenter/security/Content/2004.04.20.html
Reference: BID:9912
Reference:
URL:http://www.securityfocus.com/bid/9912
Reference: SECTRACK:1009379
Reference:
URL:http://securitytracker.com/id?1009379
Reference: SECTRACK:1009380
Reference:
URL:http://securitytracker.com/id?1009380
Reference: XF:norton-firewalls-dos(15433)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15433
Reference: XF:symantec-firewall-tcp-dos(15936)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15936
Votes:
Name: CVE-2004-0376
Description:
oftpd 0.3.6 and earlier allows remote attackers to cause
a denial of service (crash) via a PORT command with a
large value.
Status: Candidate
Phase: Assigned (20040331)
Reference: GENTOO:GLSA-200403-08
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-08.xml
Reference:
CONFIRM:http://www.time-travellers.org/oftpd/oftpd-dos.html
Reference: DEBIAN:DSA-473
Reference:
URL:http://www.debian.org/security/2004/dsa-473
Reference: BID:9980
Reference:
URL:http://www.securityfocus.com/bid/9980
Reference: SECUNIA:11220
Reference:
URL:http://secunia.com/advisories/11220
Reference: XF:oftpd-port-dos(15622)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15622
Votes:
Name: CVE-2004-0377
Description:
Buffer overflow in the win32_stat function for (1)
ActiveState's ActivePerl and (2) Larry Wall's Perl
before 5.8.3 allows local or remote attackers to execute
arbitrary commands via filenames that end in a backslash
character.
Status: Candidate
Phase: Assigned (20040331)
Reference: BUGTRAQ:20040405 [Full-Disclosure]
iDEFENSE Security Advisory 04.05.04: Perl win32_stat
Function
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108118694327979&w=2
Reference: FULLDISC:20040405 iDEFENSE Security
Advisory 04.05.04: Perl win32_stat Function
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019794.html
Reference:
MISC:http://www.idefense.com/application/poi/display?id=93&type=vulnerabilities
Reference:
CONFIRM:http://public.activestate.com/cgi-bin/perlbrowse?patch=22552
Reference: CERT-VN:VU#722414
Reference:
URL:http://www.kb.cert.org/vuls/id/722414
Reference: XF:perl-win32stat-bo(15732)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15732
Votes:
Name: CVE-2004-0378
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040402)
Votes:
Name: CVE-2004-0379
Description:
Multiple cross-site scripting (XSS) vulnerabilities in
Microsoft SharePoint Portal Server 2001 allow remote
attackers to process arbitrary web content and steal
cookies via certain server scripts.
Status: Candidate
Phase: Assigned (20040402)
Reference: BUGTRAQ:20040405 Multiple XSS
vulnerabilities in Microsoft SharePoint Portal Server
2001
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108118352303273&w=2
Reference: XF:sharepoint-portal-xss(15729)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15729
Votes:
Name: CVE-2004-0380
Description:
The MHTML protocol handler in Microsoft Outlook Express
5.5 SP2 through Outlook Express 6 SP1 allows remote
attackers to bypass domain restrictions and execute
arbitrary code, as demonstrated on Internet Explorer
using script in a compiled help (CHM) file that
references the InfoTech Storage (ITS) protocol handlers
such as (1) ms-its, (2) ms-itss, (3) its, or (4)
mk:@MSITStore, aka the "MHTML URL Processing
Vulnerability."
Status: Candidate
Phase: Assigned (20040405)
Reference: BUGTRAQ:20040219 Microsoft Internet
Explorer Unspecified CHM File Processing Arbitrary Code
Execution Vulnerability (bid 9658)
Reference:
URL:http://www.securityfocus.com/archive/1/354447
Reference: BUGTRAQ:20040328 IE ms-its: and
mk:@MSITStore: vulnerability
Reference:
URL:http://www.securityfocus.com/archive/1/358913
Reference:
MISC:http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php
Reference: MS:MS04-013
Reference:
URL:http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx
Reference: CERT:TA04-104A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT:TA04-099A
Reference: CERT-VN:VU#323070
Reference:
URL:http://www.kb.cert.org/vuls/id/323070
Reference: BID:9658
Reference:
URL:http://www.securityfocus.com/bid/9658
Reference: BID:9105
Reference:
URL:http://www.securityfocus.com/bid/9105
Reference: SECUNIA:10523
Reference:
URL:http://secunia.com/advisories/10523
Reference: XF:outlook-mhtml-execute-code(15705)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15705
Reference: OVAL:oval:org.mitre.oval:def:1010
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1010
Reference: OVAL:oval:org.mitre.oval:def:1028
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1028
Reference: OVAL:oval:org.mitre.oval:def:882
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:882
Reference: OVAL:oval:org.mitre.oval:def:990
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:990
Votes:
Name: CVE-2004-0381
Description:
mysqlbug in MySQL allows local users to overwrite
arbitrary files via a symlink attack on the
failed-mysql-bugreport temporary file.
Status: Candidate
Phase: Assigned (20040405)
Reference: BUGTRAQ:20040324 mysqlbug
tmpfile/symlink vulnerability.
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108023246916294&w=2
Reference: DEBIAN:DSA-483
Reference:
URL:http://www.debian.org/security/2004/dsa-483
Reference: GENTOO:GLSA-200405-20
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-20.xml
Reference: MANDRAKE:MDKSA-2004:034
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:034
Reference: REDHAT:RHSA-2004:569
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-569.html
Reference: REDHAT:RHSA-2004:597
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-597.html
Reference: BUGTRAQ:20040414 [OpenPKG-SA-2004.014]
OpenPKG Security Advisory (mysql)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108206802810402&w=2
Reference: CIAC:P-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/p-018.shtml
Reference: BID:9976
Reference:
URL:http://www.securityfocus.com/bid/9976
Reference: XF:mysql-mysqlbug-symlink(15617)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15617
Votes:
Name: CVE-2004-0382
Description:
Unknown vulnerability in the CUPS printing system in Mac
OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact,
possibly related to a configuration file setting.
Status: Candidate
Phase: Assigned (20040405)
Reference:
CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00047.html
Reference:
CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference:
XF:macos-cups-configuration-unknown(15769)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15769
Votes:
Name: CVE-2004-0383
Description:
Unknown vulnerability in Mail for Mac OS X 10.3.3 and
10.2.8, with unknown impact, related to "the handling of
HTML-formatted email."
Status: Candidate
Phase: Assigned (20040405)
Reference:
CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00047.html
Reference:
CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference: XF:macos-mail-unknown(15768)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15768
Votes:
Name: CVE-2004-0384
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040406)
Votes:
Name: CVE-2004-0385
Description:
Heap-based buffer overflow in Oracle 9i Application
Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and
9.0.0.4.0 allows remote attackers to execute arbitrary
code via a long HTTP request method header to the Web
Cache listener. NOTE: due to the vagueness of the Oracle
advisory, it is not clear whether there are additional
issues besides this overflow, although the advisory
alludes to multiple "vulnerabilities."
Status: Candidate
Phase: Assigned (20040406)
Reference: VULNWATCH:20040408 Heap Overflow in
Oracle 9iAS / 10g Application Server Web Cache
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0078.html
Reference: BUGTRAQ:20040408 Heap Overflow in
Oracle 9iAS / 10g Application Server Web Cache
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108144419001770&w=2
Reference:
MISC:http://www.inaccessnetworks.com/ian/services/secadv01.txt
Reference: BUGTRAQ:20040316 new security alert
#66 issued in Oracle web cache
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107945649127635&w=2
Reference:
CONFIRM:http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf
Reference: CERT-VN:VU#413006
Reference:
URL:http://www.kb.cert.org/vuls/id/413006
Reference: BID:9868
Reference:
URL:http://www.securityfocus.com/bid/9868
Reference: OSVDB:4249
Reference: URL:http://www.osvdb.org/4249
Reference: SECUNIA:11118
Reference:
URL:http://secunia.com/advisories/11118
Reference:
XF:oracle-web-cache-vulnerabilities(15463)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15463
Votes:
Name: CVE-2004-0386
Description:
Buffer overflow in the HTTP parser for MPlayer 1.0pre3
and earlier, 0.90, and 0.91 allows remote attackers to
execute arbitrary code via a long Location header.
Status: Candidate
Phase: Assigned (20040406)
Reference: BUGTRAQ:20040330 Heap overflow in
MPlayer
Reference:
URL:http://www.securityfocus.com/archive/1/359025
Reference: BUGTRAQ:20040330 MPlayer Security
Advisory #002 - HTTP parsing vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108067020624076&w=2
Reference:
CONFIRM:http://www.mplayerhq.hu/homepage/design6/news.html
Reference: GENTOO:GLSA-200403-13
Reference:
URL:http://security.gentoo.org/glsa/glsa-200403-13.xml
Reference: MANDRAKE:MDKSA-2004:026
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:026
Reference: CERT-VN:VU#723910
Reference:
URL:http://www.kb.cert.org/vuls/id/723910
Reference: BID:10008
Reference:
URL:http://www.securityfocus.com/bid/10008
Reference: SECUNIA:11259
Reference:
URL:http://secunia.com/advisories/11259
Reference: XF:mplayer-header-bo(15675)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15675
Votes:
Name: CVE-2004-0387
Description:
Stack-based buffer overflow in the RT3 plugin, as used
in RealPlayer 8, RealOne Player, RealOne Player 10 beta,
and RealOne Player Enterprise, allows remote attackers
to execute arbitrary code via a malformed .R3T file.
Status: Candidate
Phase: Assigned (20040409)
Reference: BUGTRAQ:20040307 REAL One Player R3T
File Format Stack Overflow
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108135350810135&w=2
Reference: VULNWATCH:20040307 REAL One Player R3T
File Format Stack Overflow
Reference:
URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0077.html
Reference:
MISC:http://www.ngssoftware.com/advisories/realr3t.txt
Reference:
CONFIRM:http://www.service.real.com/help/faq/security/040406_r3t/en/
Reference: BID:10070
Reference:
URL:http://www.securityfocus.com/bid/10070
Reference: OSVDB:4977
Reference:
URL:http://www.osvdb.org/displayvuln.php?osvdb_id=4977
Reference: SECUNIA:11314
Reference:
URL:http://secunia.com/advisories/11314
Reference: XF:realplayer-r3t-bo(15774)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15774
Votes:
Name: CVE-2004-0388
Description:
The mysqld_multi script in MySQL allows local users to
overwrite arbitrary files via a symlink attack.
Status: Candidate
Phase: Assigned (20040409)
Reference:
CONFIRM:http://dev.mysql.com/doc/mysql/en/news-4-1-2.html
Reference: DEBIAN:DSA-483
Reference:
URL:http://www.debian.org/security/2004/dsa-483
Reference: GENTOO:GLSA-200405-20
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-20.xml
Reference: MANDRAKE:MDKSA-2004:034
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:034
Reference: REDHAT:RHSA-2004:569
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-569.html
Reference: REDHAT:RHSA-2004:597
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-597.html
Reference: BUGTRAQ:20040414 [OpenPKG-SA-2004.014]
OpenPKG Security Advisory (mysql)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108206802810402&w=2
Reference: CIAC:P-018
Reference:
URL:http://www.ciac.org/ciac/bulletins/p-018.shtml
Reference: BID:10142
Reference:
URL:http://www.securityfocus.com/bid/10142
Reference: OSVDB:6421
Reference: URL:http://www.osvdb.org/6421
Reference: SECTRACK:1009784
Reference:
URL:http://securitytracker.com/id?1009784
Reference: SECUNIA:11223
Reference:
URL:http://secunia.com/advisories/11223/
Reference: XF:mysql-mysqldmulti-symlink(15883)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15883
Votes:
Name: CVE-2004-0389
Description:
RealNetworks Helix Universal Server 9.0.1 and 9.0.2
allows remote attackers to cause a denial of service
(crash) via malformed requests that trigger a null
dereference, as demonstrated using (1) GET_PARAMETER or
(2) DESCRIBE requests.
Status: Candidate
Phase: Assigned (20040409)
Reference: IDEFENSE:20040415 RealNetworks Helix
Universal Server Denial of Service Vulnerability
Reference:
URL:http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities
Reference: BID:10157
Reference:
URL:http://www.securityfocus.com/bid/10157
Reference: SECUNIA:11395
Reference:
URL:http://secunia.com/advisories/11395
Reference: XF:helix-get-dos(15880)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15880
Votes:
Name: CVE-2004-0390
Description:
SCO OpenServer 5.0.5 through 5.0.7 only supports
Xauthority style access control when users log in using
scologin, which allows remote attackers to gain
unauthorized access to an X session via other X login
methods.
Status: Candidate
Phase: Assigned (20040409)
Reference: FULLDISC:20040510 OpenServer 5.0.5
OpenServer 5.0.6 OpenServer 5.0.7 : X sessions which are
not started by scologin cannot use the X authorization
protocol
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html
Reference: SCO:SCOSA-2004.5
Reference:
URL:http://www.securityfocus.com/advisories/6684
Reference:
XF:openserver-x-session-insecure(16113)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16113
Votes:
Name: CVE-2004-0391
Description:
Cisco Wireless LAN Solution Engine (WLSE) 2.0 through
2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3
have a hardcoded username and password, which allows
remote attackers to add new users, modify existing
users, and change configuration.
Status: Candidate
Phase: Assigned (20040409)
Reference: CISCO:20040407 A Default Username and
Password in WLSE and HSE Devices
Reference:
URL:http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml
Reference: CERT-VN:VU#659228
Reference:
URL:http://www.kb.cert.org/vuls/id/659228
Reference: CIAC:O-111
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-111.shtml
Reference: BID:10076
Reference:
URL:http://www.securityfocus.com/bid/10076
Reference: XF:cisco-default-password(15773)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15773
Votes:
Name: CVE-2004-0392
Description:
racoon before 20040407b allows remote attackers to cause
a denial of service (infinite loop and dropped
connections) via an IKE message with a malformed Generic
Payload Header containing invalid (1) "Security
Association Next Payload" and (2) "RESERVED" fields.
Status: Candidate
Phase: Assigned (20040413)
Reference:
CONFIRM:http://www.vuxml.org/freebsd/40fcf20f-8891-11d8-90d1-0020ed76ef5a.html
Reference:
CONFIRM:http://orange.kame.net/dev/query-pr.cgi?pr=555
Reference: SCO:SCOSA-2005.10
Reference:
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
Reference: XF:racoon-isakmp-dos(15893)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15893
Votes:
Name: CVE-2004-0393
Description:
Format string vulnerability in the msg function for rlpr
daemon (rlprd) 2.0.4 allows remote attackers to execute
arbitrary code via format string specifiers in a buffer
that can not be resolved, which is provided to the
syslog function.
Status: Candidate
Phase: Assigned (20040413)
Reference: BUGTRAQ:20040624 Rlpr Advisory
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108810992313652&w=2
Reference: DEBIAN:DSA-524
Reference:
URL:http://www.debian.org/security/2004/dsa-524
Reference: BID:10578
Reference:
URL:http://www.securityfocus.com/bid/10578
Reference: XF:rlpr-msg-format-string(16453)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16453
Votes:
Name: CVE-2004-0394
Description:
A "potential" buffer overflow exists in the panic()
function in Linux 2.4.x, although it may not be
exploitable due to the functionality of panic.
Status: Candidate
Phase: Assigned (20040413)
Reference: CONECTIVA:CLA-2004:846
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-1070
Reference:
URL:http://www.debian.org/security/2006/dsa-1070
Reference: DEBIAN:DSA-1067
Reference:
URL:http://www.debian.org/security/2006/dsa-1067
Reference: DEBIAN:DSA-1069
Reference:
URL:http://www.debian.org/security/2006/dsa-1069
Reference: DEBIAN:DSA-1082
Reference:
URL:http://www.debian.org/security/2006/dsa-1082
Reference: GENTOO:GLSA-200407-02
Reference:
URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:037
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:037
Reference: MLIST:[fedora-announce] 20040422
Fedora alert FEDORA-2004-111 (kernel)
Reference: URL:http://lwn.net/Articles/81773/
Reference: ENGARDE:ESA-20040428-004
Reference:
URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: SGI:20040504-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc
Reference: SGI:20040505-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc
Reference: SUSE:SuSE-SA:2004:010
Reference:
URL:http://www.novell.com/linux/security/advisories/2004_10_kernel.html
Reference: BID:10233
Reference:
URL:http://www.securityfocus.com/bid/10233
Reference: SECUNIA:20162
Reference:
URL:http://secunia.com/advisories/20162
Reference: SECUNIA:20163
Reference:
URL:http://secunia.com/advisories/20163
Reference: SECUNIA:20202
Reference:
URL:http://secunia.com/advisories/20202
Reference: SECUNIA:20338
Reference:
URL:http://secunia.com/advisories/20338
Reference: XF:linux-panic-bo(15953)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15953
Votes:
Name: CVE-2004-0395
Description:
The xatitv program in the gatos package does not
properly drop root privileges when the configuration
file does not exist, which allows local users to execute
arbitrary commands via shell metacharacters in a system
call.
Status: Candidate
Phase: Assigned (20040413)
Reference: DEBIAN:DSA-509
Reference:
URL:http://www.debian.org/security/2004/dsa-509
Reference: BID:10437
Reference:
URL:http://www.securityfocus.com/bid/10437
Reference: XF:gatos-xatitv-gain-privileges(16273)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16273
Votes:
Name: CVE-2004-0396
Description:
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15,
and 1.12.x up to 1.12.7, when using the pserver
mechanism allows remote attackers to execute arbitrary
code via Entry lines.
Status: Candidate
Phase: Assigned (20040413)
Reference: BUGTRAQ:20040519 Advisory 07/2004: CVS
remote vulnerability
Reference:
URL:http://cert.uni-stuttgart.de/archive/bugtraq/2004/05/msg00219.html
Reference: FULLDISC:20040519 Advisory 07/2004:
CVS remote vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0980.html
Reference:
MISC:http://security.e-matters.de/advisories/072004.html
Reference: CERT:TA04-147A
Reference:
URL:http://www.us-cert.gov/cas/techalerts/TA04-147A.html
Reference: CERT-VN:VU#192038
Reference:
URL:http://www.kb.cert.org/vuls/id/192038
Reference: OPENBSD:20040520 cvs server buffer
overflow vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=openbsd-security-announce&m=108508894405639&w=2
Reference: DEBIAN:DSA-505
Reference:
URL:http://www.debian.org/security/2004/dsa-505
Reference: FEDORA:FEDORA-2004-1620
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108636445031613&w=2
Reference: FREEBSD:FreeBSD-SA-04:10
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:10.cvs.asc
Reference: GENTOO:GLSA-200405-12
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-12.xml
Reference: MANDRAKE:MDKSA-2004:048
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:048
Reference: NETBSD:NetBSD-SA2004-008
Reference:
URL:ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-008.txt.asc
Reference: REDHAT:RHSA-2004:190
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-190.html
Reference: SLACKWARE:SSA:2004-140-01
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.395865
Reference: SUSE:SuSE-SA:2004:013
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021742.html
Reference: BUGTRAQ:20040519 Advisory 07/2004: CVS
remote vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108498454829020&w=2
Reference: BUGTRAQ:20040519 [OpenPKG-SA-2004.022]
OpenPKG Security Advisory (cvs)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108500040719512&w=2
Reference: CIAC:O-147
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-147.shtml
Reference: BID:10384
Reference:
URL:http://www.securityfocus.com/bid/10384
Reference: SECUNIA:11641
Reference:
URL:http://secunia.com/advisories/11641
Reference: SECUNIA:11647
Reference:
URL:http://secunia.com/advisories/11647
Reference: SECUNIA:11651
Reference:
URL:http://secunia.com/advisories/11651
Reference: SECUNIA:11652
Reference:
URL:http://secunia.com/advisories/11652
Reference: SECUNIA:11674
Reference:
URL:http://secunia.com/advisories/11674
Reference: OSVDB:6305
Reference: URL:http://www.osvdb.org/6305
Reference: OVAL:oval:org.mitre.oval:def:970
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:970
Reference: XF:cvs-entry-line-bo(16193)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16193
Votes:
Name: CVE-2004-0397
Description:
Stack-based buffer overflow during the apr_time_t data
conversion in Subversion 1.0.2 and earlier allows remote
attackers to execute arbitrary code via a (1) DAV2
REPORT query or (2) get-dated-rev svn-protocol command.
Status: Candidate
Phase: Assigned (20040413)
Reference: FULLDISC:20040519 Advisory 08/2004:
Subversion remote vulnerability
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021737.html
Reference: BUGTRAQ:20040519 Advisory 08/2004:
Subversion remote vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108498676517697&w=2
Reference:
MISC:http://security.e-matters.de/advisories/082004.html
Reference:
CONFIRM:http://subversion.tigris.org/svn-sscanf-advisory.txt
Reference: FEDORA:FEDORA-2004-128
Reference:
URL:http://www.linuxsecurity.com/advisories/fedora_advisory-4373.html
Reference: FEDORA:FLSA:1748
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1748
Reference: GENTOO:GLSA-200405-14
Reference:
URL:http://www.gentoo.org/security/en/glsa/glsa-200405-14.xml
Reference: BUGTRAQ:20040519 [OpenPKG-SA-2004.023]
OpenPKG Security Advisory (subversion)
Reference:
URL:http://www.securityfocus.com/archive/1/363814
Reference: BID:10386
Reference:
URL:http://www.securityfocus.com/bid/10386
Reference: OSVDB:6301
Reference: URL:http://www.osvdb.org/6301
Reference: SECUNIA:11642
Reference:
URL:http://secunia.com/advisories/11642
Reference: SECUNIA:11675
Reference:
URL:http://secunia.com/advisories/11675
Reference:
XF:subversion-date-parsing-command-execution(16191)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16191
Votes:
Name: CVE-2004-0398
Description:
Heap-based buffer overflow in the ne_rfc1036_parse date
parsing function for the neon library (libneon) 0.24.5
and earlier, as used by cadaver before 0.22, allows
remote WebDAV servers to execute arbitrary code on the
client.
Status: Candidate
Phase: Assigned (20040413)
Reference: BUGTRAQ:20040519 Advisory 06/2004:
libneon date parsing vulnerability
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108498433632333&w=2
Reference: FULLDISC:20040519 Advisory 06/2004:
libneon date parsing vulnerability
Reference:
URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html
Reference: CONECTIVA:CLA-2004:841
Reference:
URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000841
Reference: REDHAT:RHSA-2004:191
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-191.html
Reference: DEBIAN:DSA-506
Reference:
URL:http://www.debian.org/security/2004/dsa-506
Reference: DEBIAN:DSA-507
Reference:
URL:http://www.debian.org/security/2004/dsa-507
Reference: FEDORA:FEDORA-2004-1552
Reference:
URL:https://bugzilla.fedora.us/show_bug.cgi?id=1552
Reference: GENTOO:GLSA-200405-13
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-13.xml
Reference: GENTOO:GLSA-200405-15
Reference:
URL:http://security.gentoo.org/glsa/glsa-200405-15.xml
Reference: MANDRAKE:MDKSA-2004:049
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:049
Reference: BUGTRAQ:20040519 [OpenPKG-SA-2004.024]
OpenPKG Security Advisory (neon)
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108500057108022&w=2
Reference: CIAC:O-148
Reference:
URL:http://www.ciac.org/ciac/bulletins/o-148.shtml
Reference: BID:10385
Reference:
URL:http://www.securityfocus.com/bid/10385
Reference: OSVDB:6302
Reference: URL:http://www.osvdb.org/6302
Reference: SECUNIA:11638
Reference:
URL:http://secunia.com/advisories/11638
Reference: SECUNIA:11650
Reference:
URL:http://secunia.com/advisories/11650
Reference: SECUNIA:11673
Reference:
URL:http://secunia.com/advisories/11673
Reference:
XF:neon-library-nerfc1036parse-bo(16192)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16192
Votes:
Name: CVE-2004-0399
Description:
Stack-based buffer overflow in Exim 3.35, and other
versions before 4, when the sender_verify option is
true, allows remote attackers to cause a denial of
service and possibly execute arbitrary code during
sender verification.
Status: Candidate
Phase: Assigned (20040413)
Reference: FULLDISC:20040506 Buffer overflows in
exim, yet still exim much better than windows
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html
Reference:
MISC:http://www.guninski.com/exim1.html
Reference: DEBIAN:DSA-501
Reference:
URL:http://www.debian.org/security/2004/dsa-501
Reference: DEBIAN:DSA-502
Reference:
URL:http://www.debian.org/security/2004/dsa-502
Reference: SECUNIA:11558
Reference:
URL:http://secunia.com/advisories/11558
Reference: XF:exim-requireverify-bo(16079)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16079
Votes:
Name: CVE-2004-0400
Description:
Stack-based buffer overflow in Exim 4 before 4.33, when
the headers_check_syntax option is enabled, allows
remote attackers to cause a denial of service and
possibly execute arbitrary code during the header check.
Status: Candidate
Phase: Assigned (20040413)
Reference: FULLDISC:20040506 Buffer overflows in
exim, yet still exim much better than windows
Reference:
URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html
Reference:
MISC:http://www.guninski.com/exim1.html
Reference: DEBIAN:DSA-501
Reference:
URL:http://www.debian.org/security/2004/dsa-501
Reference: DEBIAN:DSA-502
Reference:
URL:http://www.debian.org/security/2004/dsa-502
Reference: XF:exim-headerschecksyntax-bo(16077)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16077
Votes:
Name: CVE-2004-0401
Description:
Unknown vulnerability in libtasn1 0.1.x before 0.1.2,
and 0.2.x before 0.2.7, related to the DER parsing
functions.
Status: Candidate
Phase: Assigned (20040413)
Reference:
CONFIRM:http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog
Reference:
MISC:http://www.backports.org/changelog.html
Reference: BID:10360
Reference:
URL:http://www.securityfocus.com/bid/10360
Reference: OSVDB:15126
Reference: URL:http://www.osvdb.org/15126
Reference: SECTRACK:1010159
Reference:
URL:http://securitytracker.com/id?1010159
Reference: XF:libtasn1-der-parsing(16157)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16157
Votes:
Name: CVE-2004-0402
Description:
Buffer overflow in xpcd-svga in xpcd before 2.08, and
possibly other versions, may allow local users to
execute arbitrary code.
Status: Candidate
Phase: Assigned (20040413)
Reference: DEBIAN:DSA-508
Reference:
URL:http://www.debian.org/security/2004/dsa-508
Reference: MANDRAKE:MDKSA-2004:053
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:053
Reference: XF:xpcd-svga-pcdopen-bo(16236)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/16236
Reference: BID:10403
Reference:
URL:http://www.securityfocus.com/bid/10403
Votes:
Name: CVE-2004-0403
Description:
Racoon before 20040408a allows remote attackers to cause
a denial of service (memory consumption) via an ISAKMP
packet with a large length field.
Status: Candidate
Phase: Assigned (20040413)
Reference:
CONFIRM:http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html
Reference:
CONFIRM:http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&r2=1.181
Reference:
CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=232288
Reference: APPLE:APPLE-SA-2004-05-03
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108369640424244&w=2
Reference: GENTOO:GLSA-200404-17
Reference:
URL:http://security.gentoo.org/glsa/glsa-200404-17.xml
Reference: MANDRAKE:MDKSA-2004:069
Reference:
URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069
Reference: REDHAT:RHSA-2004:165
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-165.html
Reference: SCO:SCOSA-2005.10
Reference:
URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
Reference: SGI:20040506-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040506-01-U.asc
Reference: BID:10172
Reference:
URL:http://www.securityfocus.com/bid/10172
Reference: OSVDB:5491
Reference: URL:http://www.osvdb.org/5491
Reference: OVAL:oval:org.mitre.oval:def:984
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:984
Reference: SECTRACK:1009937
Reference:
URL:http://securitytracker.com/id?1009937
Reference: SECUNIA:11410
Reference:
URL:http://secunia.com/advisories/11410
Reference: SECUNIA:11877
Reference:
URL:http://secunia.com/advisories/11877
Reference: XF:racoon-isakmp-dos(15893)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15893
Votes:
Name: CVE-2004-0404
Description:
logcheck before 1.1.1 allows local users to overwrite
arbitrary files via a symlink attack on a temporary
directory in /var/tmp.
Status: Candidate
Phase: Assigned (20040414)
Reference: DEBIAN:DSA-488
Reference:
URL:http://www.debian.org/security/2004/dsa-488
Reference: MANDRAKE:MDKSA-2004:155
Reference:
URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:155
Reference: BID:10162
Reference:
URL:http://www.securityfocus.com/bid/10162
Reference: SECUNIA:11399
Reference:
URL:http://secunia.com/advisories/11399
Reference: XF:logcheck-directory-symlink(15888)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15888
Votes:
Name: CVE-2004-0405
Description:
CVS before 1.11 allows CVS clients to read arbitrary
files via .. (dot dot) sequences in filenames via CVS
client requests, a different vulnerability than
CVE-2004-0180.
Status: Candidate
Phase: Assigned (20040416)
Reference: DEBIAN:DSA-486
Reference:
URL:http://www.debian.org/security/2004/dsa-486
Reference: FREEBSD:FreeBSD-SA-04:07
Reference:
URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc
Reference: FEDORA:FEDORA-2004-1620
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108636445031613&w=2
Reference: GENTOO:GLSA-200404-13
Reference:
URL:http://security.gentoo.org/glsa/glsa-200404-13.xml
Reference: SGI:20040404-01-U
Reference:
URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
Reference: SLACKWARE:SSA:2004-108-02
Reference:
URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.400181
Reference: OVAL:oval:org.mitre.oval:def:1060
Reference:
URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1060
Reference:
XF:cvs-dotdot-directory-traversal(15891)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15891
Votes:
Name: CVE-2004-0406
Description:
** RESERVED ** This candidate has been reserved by an
organization or individual that will use it when
announcing a new security problem. When the candidate
has been publicized, the details for this candidate will
be provided.
Status: Candidate
Phase: Assigned (20040416)
Votes:
Name: CVE-2004-0407
Description:
The HTML form upload capability in ColdFusion MX 6.1
does not reclaim disk space if an upload is interrupted,
which allows remote attackers to cause a denial of
service (disk consumption) by repeatedly uploading files
and interrupting the uploads before they finish.
Status: Candidate
Phase: Assigned (20040416)
Reference: BUGTRAQ:20040416
[securityzone@macromedia.com: New Macromedia Security
Zone Bulletin Posted]
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213782629001&w=2
Reference:
CONFIRM:http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.html
Reference: BID:10158
Reference:
URL:http://www.securityfocus.com/bid/10158
Reference: OSVDB:5402
Reference: URL:http://www.osvdb.org/5402
Reference: SECTRACK:1009825
Reference:
URL:http://securitytracker.com/id?1009825
Reference: SECUNIA:11392
Reference:
URL:http://secunia.com/advisories/11392
Reference: XF:coldfusion-upload-file-dos(15882)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15882
Votes:
Name: CVE-2004-0408
Description:
Buffer overflow in the child_service function in the
ident2 ident daemon allows remote attackers to execute
arbitrary code.
Status: Candidate
Phase: Assigned (20040416)
Reference: DEBIAN:DSA-494
Reference:
URL:http://www.debian.org/security/2004/dsa-494
Reference: BID:10192
Reference:
URL:http://www.securityfocus.com/bid/10192
Reference: XF:ident2-childservice-bo(15938)
Reference:
URL:http://xforce.iss.net/xforce/xfdb/15938
Votes:
Name: CVE-2004-0409
Description:
Stack-based buffer overflow in the Socks-5 proxy code
for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled,
allows remote attackers to execute arbitrary code.
Status: Candidate
Phase: Assigned (20040416)
Reference: MLIST:[xchat-announce] 20040405 xchat
2.0.x Socks5 Vulnerability
Reference:
URL:http://mail.nl.linux.org/xchat-announce/2004-04/msg00000.html
Reference: CONFIRM:http://www.xchat.org/
Reference: DEBIAN:DSA-493
Reference:
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108258002427226&w=2
Reference: FEDORA:FLSA:123013
Reference:
URL:http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_123013
Reference: REDHAT:RHSA-2004:177
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-177.html
Reference: REDHAT:RHSA-2004:585
Reference:
URL:http://www.redhat.com/support/errata/RHSA-2004-585.html
Reference: GENTOO:GLSA-200404-15
Reference:
URL:http://security.gentoo.org/glsa/glsa-200404-15.xml
Votes:
Name: CVE-2004-0410
Description:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER.
ConsultIDs: none. Reason: This candidate was withdrawn
by its CNA. Further investigation showed that it was not
a security issue. Notes: none.
Status: Candidate
Phase: Assigned (20040416)
Votes:
Name: CVE-2004-0411
Descrip |