Support

 Sax2 Network Intrusion Detection System

A professional intrusion detection and prevention  system (NIDS) which excels at real-time packet capture, 24/7 network monitor, advanced protocol analysis and automatic expert detection.  

 

CAN-2004
 

Name: CVE-2004-0002

 

Description:
The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.

Status: Candidate
Phase: Proposed (20040318)
Reference: CONFIRM:http://lists.freebsd.org/pipermail/cvs-src/2004-January/016271.html
 

Votes:

   ACCEPT(4) Williams, Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0003

 

Description:
Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."

Status: Candidate
Phase: Modified (20061101)
Reference: CONFIRM:http://www.linuxcompatible.org/print25630.html
Reference: DEBIAN:DSA-479
Reference: URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference: URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference: URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference: URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference: URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference: URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference: URL:http://www.debian.org/security/2004/dsa-495
Reference: MANDRAKE:MDKSA-2004:029
Reference: URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:044
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-044.html
Reference: REDHAT:RHSA-2004:065
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-065.html
Reference: REDHAT:RHSA-2004:106
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-106.html
Reference: REDHAT:RHSA-2004:166
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-166.html
Reference: SUSE:SuSE-SA:2004:005
Reference: URL:http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html
Reference: TURBO:TLSA-2004-14
Reference: URL:http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
Reference: CIAC:O-082
Reference: URL:http://www.ciac.org/ciac/bulletins/o-082.shtml
Reference: CIAC:O-121
Reference: URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-126
Reference: URL:http://www.ciac.org/ciac/bulletins/o-126.shtml
Reference: CIAC:O-127
Reference: URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: CIAC:O-145
Reference: URL:http://www.ciac.org/ciac/bulletins/o-145.shtml
Reference: BID:9570
Reference: URL:http://www.securityfocus.com/bid/9570
Reference: SECUNIA:10782
Reference: URL:http://secunia.com/advisories/10782
Reference: SECUNIA:10911
Reference: URL:http://secunia.com/advisories/10911
Reference: SECUNIA:10912
Reference: URL:http://secunia.com/advisories/10912
Reference: SECUNIA:11202
Reference: URL:http://secunia.com/advisories/11202
Reference: SECUNIA:11361
Reference: URL:http://secunia.com/advisories/11361
Reference: SECUNIA:11362
Reference: URL:http://secunia.com/advisories/11362
Reference: SECUNIA:11369
Reference: URL:http://secunia.com/advisories/11369
Reference: SECUNIA:11370
Reference: URL:http://secunia.com/advisories/11370
Reference: SECUNIA:11376
Reference: URL:http://secunia.com/advisories/11376
Reference: SECUNIA:11464
Reference: URL:http://secunia.com/advisories/11464
Reference: SECUNIA:11891
Reference: URL:http://secunia.com/advisories/11891
Reference: SECUNIA:12075
Reference: URL:http://secunia.com/advisories/12075
Reference: OVAL:oval:org.mitre.oval:def:1017
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017
Reference: OVAL:oval:org.mitre.oval:def:834
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834
Reference: XF:linux-r128-gain-priviliges(15029)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15029
 

Votes:

   ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
   NOOP(2) Christey, Wall
Voter Comments:
 
 Christey> DEBIAN:DSA-479
   URL:http://www.debian.org/security/2004/dsa-479
   DEBIAN:DSA-480
   URL:http://www.debian.org/security/2004/dsa-480
   DEBIAN:DSA-481
   URL:http://www.debian.org/security/2004/dsa-481
   DEBIAN:DSA-482
   URL:http://www.debian.org/security/2004/dsa-482
 Christey> DEBIAN:DSA-489
   URL:http://www.debian.org/security/2004/dsa-489
   DEBIAN:DSA-491
   URL:http://www.debian.org/security/2004/dsa-491
 Christey> DEBIAN:DSA-495
   URL:http://www.debian.org/security/2004/dsa-495
   REDHAT:RHSA-2004:166
   URL:http://rhn.redhat.com/errata/RHSA-2004-166.html
 Christey> REDHAT:RHSA-2004:188
   URL:http://www.redhat.com/support/errata/RHSA-2004-188.html
 Christey> CONECTIVA:CLA-2004:846
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846


Name: CVE-2004-0005

 

Description:
Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference: MISC:http://security.e-matters.de/advisories/012004.html
Reference: CONECTIVA:CLA-2004:813
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: DEBIAN:DSA-434
Reference: URL:http://www.debian.org/security/2004/dsa-434
Reference: GENTOO:GLSA-200401-04
Reference: URL:http://www.linuxsecurity.com/content/view/105690/104/
Reference: SLACKWARE:SSA:2004-026
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
Reference: SUSE:SuSE-SA:2004:004
Reference: URL:http://www.novell.com/linux/security/advisories/2004_04_gaim.html
Reference: CERT-VN:VU#190366
Reference: URL:http://www.kb.cert.org/vuls/id/190366
Reference: CERT-VN:VU#226974
Reference: URL:http://www.kb.cert.org/vuls/id/226974
Reference: CERT-VN:VU#404470
Reference: URL:http://www.kb.cert.org/vuls/id/404470
Reference: CERT-VN:VU#655974
Reference: URL:http://www.kb.cert.org/vuls/id/655974
Reference: OSVDB:3736
Reference: URL:http://www.osvdb.org/3736
Reference: SECTRACK:1008850
Reference: URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-mime-decoder-bo(14942)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14942
Reference: XF:gaim-mime-decoder-oob(14944)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14944
Reference: XF:gaim-yahoodecode-offbyone-bo(14935)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14935
Reference: XF:gaim-sscanf-oob(14938)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14938
 

Votes:

   ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
   NOOP(2) Christey, Wall
Voter Comments:
 
 Christey> CERT-VN:VU#404470
   URL:http://www.kb.cert.org/vuls/id/404470
   CERT-VN:VU#655974
   URL:http://www.kb.cert.org/vuls/id/655974
   CERT-VN:VU#226974
   URL:http://www.kb.cert.org/vuls/id/226974
   CERT-VN:VU#190366
   URL:http://www.kb.cert.org/vuls/id/190366


Name: CVE-2004-0006

 

Description:
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference: MISC:http://security.e-matters.de/advisories/012004.html
Reference: BUGTRAQ:20040127 Ultramagnetic Advisory #001: Multiple vulnerabilities in Gaim code
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522432613022&w=2
Reference: CONFIRM:http://ultramagnetic.sourceforge.net/advisories/001.html
Reference: REDHAT:RHSA-2004:032
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-032.html
Reference: REDHAT:RHSA-2004:033
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-033.html
Reference: REDHAT:RHSA-2004:045
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-045.html
Reference: MANDRAKE:MDKSA-2004:006
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:006
Reference: SGI:20040202-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: SUSE:SuSE-SA:2004:004
Reference: URL:http://www.novell.com/linux/security/advisories/2004_04_gaim.html
Reference: DEBIAN:DSA-434
Reference: URL:http://www.debian.org/security/2004/dsa-434
Reference: CONECTIVA:CLA-2004:813
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: SGI:20040201-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
Reference: SLACKWARE:SSA:2004-026
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
Reference: GENTOO:GLSA-200401-04
Reference: URL:http://security.gentoo.org/glsa/glsa-200401-04.xml
Reference: CERT-VN:VU#297198
Reference: URL:http://www.kb.cert.org/vuls/id/297198
Reference: CERT-VN:VU#371382
Reference: URL:http://www.kb.cert.org/vuls/id/371382
Reference: CERT-VN:VU#444158
Reference: URL:http://www.kb.cert.org/vuls/id/444158
Reference: CERT-VN:VU#503030
Reference: URL:http://www.kb.cert.org/vuls/id/503030
Reference: CERT-VN:VU#527142
Reference: URL:http://www.kb.cert.org/vuls/id/527142
Reference: CERT-VN:VU#871838
Reference: URL:http://www.kb.cert.org/vuls/id/871838
Reference: BID:9489
Reference: URL:http://www.securityfocus.com/bid/9489
Reference: OSVDB:3731
Reference: URL:http://www.osvdb.org/3731
Reference: OSVDB:3732
Reference: URL:http://www.osvdb.org/3732
Reference: OVAL:oval:org.mitre.oval:def:818
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:818
Reference: SECTRACK:1008850
Reference: URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-http-proxy-bo(14947)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14947
Reference: XF:gaim-login-name-bo(14940)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14940
Reference: XF:gaim-login-value-bo(14941)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14941
Reference: XF:gaim-urlparser-bo(14945)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14945
Reference: XF:gaim-yahoopacketread-keyname-bo(14943)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14943
Reference: XF:gaim-yahoowebpending-cookie-bo(14939)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14939
 

Votes:

   ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
   NOOP(2) Christey, Wall
Voter Comments:
 
 Cox> Although the 0.59.1 version of Gaim shipped by Red Hat contained these
   flaws, Yahoo connections were not functional and therefore the majority of
   the issues could not be exploited, leading to the abstraction comment above.
 Christey> CERT-VN:VU#871838
   URL:http://www.kb.cert.org/vuls/id/871838
   CERT-VN:VU#444158
   URL:http://www.kb.cert.org/vuls/id/444158
   CERT-VN:VU#503030
   URL:http://www.kb.cert.org/vuls/id/503030
   CERT-VN:VU#371382
   URL:http://www.kb.cert.org/vuls/id/371382
   CERT-VN:VU#297198
   URL:http://www.kb.cert.org/vuls/id/297198
   CERT-VN:VU#527142
   URL:http://www.kb.cert.org/vuls/id/527142
 Christey> Normalize Gentoo reference


Name: CVE-2004-0007

 

Description:
Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference: MISC:http://security.e-matters.de/advisories/012004.html
Reference: BUGTRAQ:20040127 Ultramagnetic Advisory #001: Multiple vulnerabilities in Gaim code
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522432613022&w=2
Reference: CONFIRM:http://ultramagnetic.sourceforge.net/advisories/001.html
Reference: CONECTIVA:CLA-2004:813
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: DEBIAN:DSA-434
Reference: URL:http://www.debian.org/security/2004/dsa-434
Reference: GENTOO:GLSA-200401-04
Reference: URL:http://security.gentoo.org/glsa/glsa-200401-04.xml
Reference: MANDRAKE:MDKSA-2004:006
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:006
Reference: REDHAT:RHSA-2004:032
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-032.html
Reference: REDHAT:RHSA-2004:033
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-033.html
Reference: SLACKWARE:SSA:2004-026
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
Reference: SUSE:SuSE-SA:2004:004
Reference: URL:http://www.securityfocus.com/advisories/6281
Reference: CERT-VN:VU#197142
Reference: URL:http://www.kb.cert.org/vuls/id/197142
Reference: BID:9489
Reference: URL:http://www.securityfocus.com/bid/9489
Reference: OSVDB:3733
Reference: URL:http://www.osvdb.org/3733
Reference: OVAL:oval:org.mitre.oval:def:819
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:819
Reference: SECTRACK:1008850
Reference: URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-extractinfo-bo(14946)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14946
 

Votes:

   ACCEPT(5) Green, Baker, Cole, Armstrong, Cox
   NOOP(2) Christey, Wall
Voter Comments:
 
 Christey> Normalize Gentoo, Slackware reference
 Christey> CERT-VN:VU#197142


Name: CVE-2004-0008

 

Description:
Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107513690306318&w=2
Reference: FULLDISC:20040126 Advisory 01/2004: 12 x Gaim remote overflows
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Reference: MISC:http://security.e-matters.de/advisories/012004.html
Reference: BUGTRAQ:20040127 Ultramagnetic Advisory #001: Multiple vulnerabilities in Gaim code
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522432613022&w=2
Reference: CONFIRM:http://ultramagnetic.sourceforge.net/advisories/001.html
Reference: REDHAT:RHSA-2004:032
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-032.html
Reference: REDHAT:RHSA-2004:033
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-033.html
Reference: MANDRAKE:MDKSA-2004:006
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:006
Reference: DEBIAN:DSA-434
Reference: URL:http://www.debian.org/security/2004/dsa-434
Reference: REDHAT:RHSA-2004:045
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-045.html
Reference: CONECTIVA:CLA-2004:813
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Reference: SGI:20040201-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
Reference: BUGTRAQ:20040127 [slackware-security] GAIM security update (SSA:2004-026-01)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107522338611564&w=2
Reference: GENTOO:GLSA-200401-04
Reference: URL:http://security.gentoo.org/glsa/glsa-200401-04.xml
Reference: SGI:20040202-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: CERT-VN:VU#779614
Reference: URL:http://www.kb.cert.org/vuls/id/779614
Reference: OSVDB:3734
Reference: URL:http://www.osvdb.org/3734
Reference: OVAL:oval:org.mitre.oval:def:820
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:820
Reference: SECTRACK:1008850
Reference: URL:http://www.securitytracker.com/id?1008850
Reference: XF:gaim-directim-bo(14937)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14937
 

Votes:

   ACCEPT(6) Green, Wall, Baker, Cole, Armstrong, Cox
   NOOP(1) Christey
Voter Comments:
 
 Christey> CERT-VN:VU#779614


Name: CVE-2004-0010

 

Description:
Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.

Status: Candidate
Phase: Assigned (20040105)
Reference: CONECTIVA:CLA-2004:820
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000820
Reference: DEBIAN:DSA-479
Reference: URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference: URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference: URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference: URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference: URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference: URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference: URL:http://www.debian.org/security/2004/dsa-495
Reference: FEDORA:FEDORA-2004-079
Reference: URL:http://fedoranews.org/updates/FEDORA-2004-079.shtml
Reference: MANDRAKE:MDKSA-2004:015
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:015
Reference: REDHAT:RHSA-2004:065
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-065.html
Reference: REDHAT:RHSA-2004:069
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-069.html
Reference: REDHAT:RHSA-2004:188
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-188.html
Reference: SUSE:SuSE-SA:2004:005
Reference: URL:http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html
Reference: TURBO:TLSA-2004-05
Reference: URL:http://www.securityfocus.com/advisories/6759
Reference: CIAC:O-082
Reference: URL:http://www.ciac.org/ciac/bulletins/o-082.shtml
Reference: BID:9691
Reference: URL:http://www.securityfocus.com/bid/9691
Reference: XF:linux-ncplookup-gain-privileges(15250)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15250
Reference: OVAL:oval:org.mitre.oval:def:1035
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1035
Reference: OVAL:oval:org.mitre.oval:def:835
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:835
 

Votes:

 

Name: CVE-2004-0012

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040105)
 

Votes:

 

Name: CVE-2004-0014

 

Description:
Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.

Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-412
Reference: URL:http://www.debian.org/security/2004/dsa-412
Reference: BID:9365
Reference: URL:http://www.securityfocus.com/bid/9365
Reference: SECTRACK:1008616
Reference: URL:http://www.securitytracker.com/id?1008616
Reference: SECUNIA:10549
Reference: URL:http://secunia.com/advisories/10549
Reference: SECUNIA:10550
Reference: URL:http://secunia.com/advisories/10550
Reference: XF:nd-long-string-bo(14141)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14141
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   MODIFY(1) Williams
   NOOP(2) Wall, Cox
Voter Comments:
 
 Williams> need to change desc.  i think this was fixed in 0.8.2.
   http://www.gohome.org/nd


Name: CVE-2004-0017

 

Description:
Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.

Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-419
Reference: URL:http://www.debian.org/security/2004/dsa-419
Reference: BID:9386
Reference: URL:http://www.securityfocus.com/bid/9386
Reference: SECTRACK:1008662
Reference: URL:http://www.securitytracker.com/id?1008662
Reference: SECUNIA:10591
Reference: URL:http://secunia.com/advisories/10591
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   MODIFY(1) Williams
   NOOP(2) Wall, Cox
Voter Comments:
 
 Williams> i believe this affects phpGroupWare 0.9.14.006 and earlier, and phpGroupWare 0.9.16RC1 and earlier.
   http://phpgroupware.org/downloads


Name: CVE-2004-0018

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0019

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0020

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0021

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0022

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0023

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0024

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0025

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0026

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0027

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040106)
 

Votes:

 

Name: CVE-2004-0029

 

Description:
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040106 Lotus Notes Domino 6.0.2 (linux) faulty default permissions
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340897710308&w=2
Reference: MISC:http://www.excluded.org/advisories/advisory05.txt
Reference: BID:9366
Reference: URL:http://www.securityfocus.com/bid/9366
Reference: OSVDB:3424
Reference: URL:http://www.osvdb.org/3424
Reference: SECTRACK:1008623
Reference: URL:http://www.securitytracker.com/id?1008623
Reference: SECUNIA:10566
Reference: URL:http://secunia.com/advisories/10566
Reference: XF:lotus-notes-insecure-permissions(14153)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14153
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
 
 Williams> insufficient data.


Name: CVE-2004-0030

 

Description:
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040106 Vuln in PHPGEDVIEW 2.61 Multi-Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340840209453&w=2
Reference: BID:9368
Reference: URL:http://www.securityfocus.com/bid/9368
Reference: OSVDB:3343
Reference: URL:http://www.osvdb.org/3343
Reference: SECTRACK:1008632
Reference: URL:http://www.securitytracker.com/id?1008632
Reference: SECUNIA:10565
Reference: URL:http://secunia.com/advisories/10565
Reference: XF:phpgedview-pgvbasedirectory-file-include(14159)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14159
 

Votes:

   ACCEPT(3) Williams, Baker, Armstrong
   NOOP(3) Wall, Cole, Cox
Voter Comments:
 
 Williams> http://phpgedview.sourceforge.net/


Name: CVE-2004-0034

 

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040105 Multiple Vulnerabilities in Phorum 3.4.5
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340481804110&w=2
Reference: CONFIRM:http://phorum.org/
Reference: BID:9361
Reference: URL:http://www.securityfocus.com/bid/9361
Reference: OSVDB:3434
Reference: URL:http://www.osvdb.org/3434
Reference: OSVDB:3506
Reference: URL:http://www.osvdb.org/3506
Reference: OSVDB:3510
Reference: URL:http://www.osvdb.org/3510
Reference: SECTRACK:1008633
Reference: URL:http://www.securitytracker.com/id?1008633
Reference: SECUNIA:10567
Reference: URL:http://secunia.com/advisories/10567
Reference: XF:phorum-common-xss(14145)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14145
 

Votes:

   ACCEPT(4) Williams, Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0037

 

Description:
FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040105 FirstClass Client 7.1: Command Execution via Email Web Link
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107340950611167&w=2
Reference: BID:9370
Reference: URL:http://www.securityfocus.com/bid/9370
Reference: OSVDB:3442
Reference: URL:http://www.osvdb.org/3442
Reference: SECTRACK:1008609
Reference: URL:http://www.securitytracker.com/id?1008609
Reference: SECUNIA:10556
Reference: URL:http://secunia.com/advisories/10556
Reference: XF:firstclassclient-execute-code(14151)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14151
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
 
 Williams> insufficient data.


Name: CVE-2004-0038

 

Description:
McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.

Status: Candidate
Phase: Assigned (20040107)
Reference: ISS:20040510 McAfee ePolicy Orchestrator Remote Compromise Vulnerability
Reference: URL:http://xforce.iss.net/xforce/alerts/id/173
Reference: CONFIRM:http://download.nai.com/products/patches/ePO/v2.x/Patch14.txt
Reference: MISC:http://www.osvdb.org/5626
Reference: XF:epolicy-execute-commands(14166)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14166
Reference: BID:10200
Reference: URL:http://www.securityfocus.com/bid/10200
 

Votes:

 

Name: CVE-2004-0039

 

Description:
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.

Status: Candidate
Phase: Modified (20050818)
Reference: ISS:20040204 Checkpoint Firewall-1 HTTP Parsing Format String Vulnerabilities
Reference: URL:http://xforce.iss.net/xforce/alerts/id/162
Reference: BUGTRAQ:20040205 Two checkpoint fw-1/vpn-1 vulns
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107604682227031&w=2
Reference: CONFIRM:http://www.checkpoint.com/techsupport/alerts/security_server.html
Reference: CERT:TA04-036A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-036A.html
Reference: CERT-VN:VU#790771
Reference: URL:http://www.kb.cert.org/vuls/id/790771
Reference: CIAC:O-072
Reference: URL:http://www.ciac.org/ciac/bulletins/o-072.shtml
Reference: XF:fw1-format-string(14149)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14149
Reference: BID:9581
Reference: URL:http://www.securityfocus.com/bid/9581
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   NOOP(1) Cox

Name: CVE-2004-0041

 

Description:
The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.

Status: Candidate
Phase: Assigned (20040107)
Reference: DEBIAN:DSA-421
Reference: URL:http://www.debian.org/security/2004/dsa-421
Reference: BID:9404
Reference: URL:http://www.securityfocus.com/bid/9404
Reference: OSVDB:3454
Reference: URL:http://www.osvdb.org/3454
Reference: SECTRACK:1008675
Reference: URL:http://www.securitytracker.com/id?1008675
Reference: SECUNIA:10612
Reference: URL:http://secunia.com/advisories/10612
 

Votes:

 

Name: CVE-2004-0042

 

Description:
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.

Status: Candidate
Phase: Modified (20050526)
Reference: SECTRACK:1008628
Reference: URL:http://securitytracker.com/id?1008628
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(3) Williams, Wall, Cole
   REJECT(1) Cox
Voter Comments:
 
 Williams> insufficient data.
 CHANGE> [Cox changed vote from REVIEWING to REJECT]
 Cox> Expected behaviour.  By source code analysis the difference in
   behaviour mentioned in the report only occurs when an administrator has
   configured the server with an explicit userlist - either to allow or deny
   all users in the userlist.  The vsftpd manual page states that if a
   userlist is used then the user will be denied access before they are asked
   for a password to help prevent cleartext passwords being transmitted.  
   Administrators who don't want this behaviour do not need to configure an
   optional userlist.


Name: CVE-2004-0043

 

Description:
Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107357996802255&w=2
Reference: FULLDISC:20040108 Yahoo Instant Messenger Long Filename Downloading Buffer Overflow
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015334.html
Reference: BID:9383
Reference: URL:http://www.securityfocus.com/bid/9383
Reference: OSVDB:3437
Reference: URL:http://www.osvdb.org/3437
Reference: SECTRACK:1008651
Reference: URL:http://www.securitytracker.com/id?1008651
Reference: SECUNIA:10573
Reference: URL:http://secunia.com/advisories/10573
Reference: XF:yahoo-messenger-filename-bo(14171)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14171
 

Votes:

   ACCEPT(3) Williams, Baker, Armstrong
   NOOP(2) Cole, Cox
   REVIEWING(1) Wall
Voter Comments:
 
 Williams> http://lists.netsys.com/pipermail/full-disclosure/2004-January/015355.html
   http://www.packetstormsecurity.nl/0401-advisories/yahooIM.txt


Name: CVE-2004-0046

 

Description:
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.

Status: Candidate
Phase: Modified (20050430)
Reference: BUGTRAQ:20040106 SnapStream PVS LITE Cross Site Scripting Vulnerabillity
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107350313917867&w=2
Reference: BID:9375
Reference: URL:http://www.securityfocus.com/bid/9375
Reference: OSVDB:3440
Reference: URL:http://www.osvdb.org/3440
Reference: SECTRACK:1008646
Reference: URL:http://securitytracker.com/id?1008646
Reference: SECUNIA:10575
Reference: URL:http://secunia.com/advisories/10575
Reference: XF:snapstream-quotation-xss(14164)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14164
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
 
 Williams> insufficient data.


Name: CVE-2004-0047

 

Description:
Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.

Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-430
Reference: URL:http://www.debian.org/security/2004/dsa-430
Reference: BID:9520
Reference: URL:http://www.securityfocus.com/bid/9520
Reference: OSVDB:3747
Reference: URL:http://www.osvdb.org/3747
Reference: SECTRACK:1008875
Reference: URL:http://www.securitytracker.com/id?1008875
Reference: SECUNIA:10744
Reference: URL:http://secunia.com/advisories/10744/
Reference: SECUNIA:10745
Reference: URL:http://secunia.com/advisories/10745
Reference: XF:trr19-gain-privileges(14975)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14975
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0048

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040113)
 

Votes:

 

Name: CVE-2004-0050

 

Description:
Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.

Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108377388114888&w=2
Reference: VULNWATCH:20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q2/0024.html
Reference: FULLDISC:20040505 Corsaire Security Advisory - Verity Ultraseek path disclosure issue
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020952.html
Reference: XF:ultraseek-error-path-disclosure(16066)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16066
 

Votes:

 

Name: CVE-2004-0051

 

Description:
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.

Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040914 Corsaire Security Advisory - Multiple vendor MIME Content-Transfer-Encoding mechanism issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109517788100063&w=2
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference: XF:mime-contenttransfer-filter-bypass(17337)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17337
 

Votes:

 

Name: CVE-2004-0052

 

Description:
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.

Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040914 Corsaire Security Advisory - Multiple vendor MIME separator issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109517669115891&w=2
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference: XF:mime-separator-filtering-bypass(17334)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17334
 

Votes:

 

Name: CVE-2004-0053

 

Description:
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.

Status: Candidate
Phase: Assigned (20040114)
Reference: BUGTRAQ:20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109520704408739&w=2
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference: XF:mime-rfc2047-filtering-bypass(17331)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17331
 

Votes:

 

Name: CVE-2004-0054

 

Description:
Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

Status: Candidate
Phase: Modified (20071113)
Reference: CISCO:20040113 Vulnerabilities in H.323 Message Processing
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040113-h323.shtml
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
Reference: CERT:CA-2004-01
Reference: URL:http://www.cert.org/advisories/CA-2004-01.html
Reference: CERT-VN:VU#749342
Reference: URL:http://www.kb.cert.org/vuls/id/749342
Reference: BID:9406
Reference: URL:http://www.securityfocus.com/bid/9406
Reference: SECTRACK:1008685
Reference: URL:http://www.securitytracker.com/id?1008685
 

Votes:

   ACCEPT(5) Green, Wall, Baker, Cole, Armstrong
   NOOP(1) Cox

Name: CVE-2004-0055

 

Description:
The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.

Status: Candidate
Phase: Modified (20071129)
Reference: MLIST:[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1
Reference: URL:http://marc.theaimsgroup.com/?l=tcpdump-workers&m=107325073018070&w=2
Reference: APPLE:APPLE-SA-2004-02-23
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: CONECTIVA:CLSA-2003:832
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000832
Reference: FEDORA:FLSA:1222
Reference: URL:http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html
Reference: REDHAT:RHSA-2004:008
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-008.html
Reference: DEBIAN:DSA-425
Reference: URL:http://www.debian.org/security/2004/dsa-425
Reference: MANDRAKE:MDKSA-2004:008
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:008
Reference: SGI:20040103-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
Reference: BUGTRAQ:20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577418225627&w=2
Reference: SGI:20040202-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: CERT-VN:VU#955526
Reference: URL:http://www.kb.cert.org/vuls/id/955526
Reference: BID:7090
Reference: URL:http://www.securityfocus.com/bid/7090
Reference: OVAL:oval:org.mitre.oval:def:850
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:850
Reference: OVAL:oval:org.mitre.oval:def:853
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:853
Reference: SECTRACK:1008735
Reference: URL:http://www.securitytracker.com/id?1008735
 

Votes:

   ACCEPT(6) Williams, Wall, Baker, Cole, Armstrong, Cox
   NOOP(1) Christey
Voter Comments:
 
 Cox> ADDREF: REDHAT:RHSA-2004:007
 Williams> http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-isakmp.c
 Christey> SCO:SCOSA-2004.9
   URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt


Name: CVE-2004-0056

 

Description:
Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

Status: Candidate
Phase: Modified (20071113)
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
Reference: CERT:CA-2004-01
Reference: URL:http://www.cert.org/advisories/CA-2004-01.html
Reference: CERT-VN:VU#749342
Reference: URL:http://www.kb.cert.org/vuls/id/749342
Reference: BID:9406
Reference: URL:http://www.securityfocus.com/bid/9406
Reference: SECTRACK:1008687
Reference: URL:http://www.securitytracker.com/id?1008687
 

Votes:

   ACCEPT(3) Green, Baker, Armstrong
   NOOP(3) Wall, Cole, Cox

Name: CVE-2004-0057

 

Description:
The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.

Status: Candidate
Phase: Modified (20071113)
Reference: MLIST:[tcpdump-workers] multiple vulnerabilities in tcpdump 3.8.1
Reference: URL:http://marc.theaimsgroup.com/?l=tcpdump-workers&m=107325073018070&w=2
Reference: APPLE:APPLE-SA-2004-02-23
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: FEDORA:FLSA:1222
Reference: URL:http://www.redhat.com/archives/fedora-legacy-list/2004-January/msg00726.html
Reference: REDHAT:RHSA-2004:007
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-007.html
Reference: REDHAT:RHSA-2004:008
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-008.html
Reference: DEBIAN:DSA-425
Reference: URL:http://www.debian.org/security/2004/dsa-425
Reference: MANDRAKE:MDKSA-2004:008
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:008
Reference: SGI:20040103-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040103-01-U.asc
Reference: BUGTRAQ:20040131 [FLSA-2004:1222] Updated tcpdump resolves security vulnerabilites (resend with correct paths)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577418225627&w=2
Reference: SGI:20040202-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
Reference: CERT-VN:VU#174086
Reference: URL:http://www.kb.cert.org/vuls/id/174086
Reference: BID:9423
Reference: URL:http://www.securityfocus.com/bid/9423
Reference: OVAL:oval:org.mitre.oval:def:851
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:851
Reference: OVAL:oval:org.mitre.oval:def:854
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:854
Reference: SECTRACK:1008716
Reference: URL:http://www.securitytracker.com/id?1008716
Reference: SECUNIA:10636
Reference: URL:http://secunia.com/advisories/10636
Reference: XF:tcpdump-rawprint-isakmp-dos(14837)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14837
 

Votes:

   ACCEPT(6) Green, Wall, Baker, Cole, Armstrong, Cox
   NOOP(1) Christey
Voter Comments:
 
 Christey> SCO:SCOSA-2004.9
   URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.9/SCOSA-2004.9.txt


Name: CVE-2004-0058

 

Description:
Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040113 symlink vul for Antivir / Linux Version 2.0.9-9 (maybe lower)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107402026023763&w=2
Reference: OSVDB:3496
Reference: URL:http://www.osvdb.org/3496
Reference: SECTRACK:1008702
Reference: URL:http://www.securitytracker.com/id?1008702
Reference: SECUNIA:10620
Reference: URL:http://secunia.com/advisories/10620
Reference: XF:antivir-tmpfile-insecure(14214)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14214
 

Votes:

   ACCEPT(1) Baker
   NOOP(4) Wall, Cole, Armstrong, Cox
   REVIEWING(1) Green

Name: CVE-2004-0059

 

Description:
Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 Multiple vulnerabilities in WWW Fileshare Pro <= 2.42
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411794303201&w=2
Reference: SECTRACK:1008779
Reference: URL:http://www.securitytracker.com/id?1008779
 

Votes:

   ACCEPT(2) Baker, Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0060

 

Description:
WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 Multiple vulnerabilities in WWW Fileshare Pro <= 2.42
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411794303201&w=2
Reference: SECTRACK:1008779
Reference: URL:http://www.securitytracker.com/id?1008779
 

Votes:

   ACCEPT(2) Green, Baker
   NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
 
 Green> Acknowledged in 2.46 release notes


Name: CVE-2004-0061

 

Description:
WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 Multiple vulnerabilities in WWW Fileshare Pro <= 2.42
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411794303201&w=2
Reference: SECTRACK:1008779
Reference: URL:http://www.securitytracker.com/id?1008779
 

Votes:

   ACCEPT(2) Green, Baker
   NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
 
 Green> Ack'ed in 2.46 release notes


Name: CVE-2004-0062

 

Description:
Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040114 FishCart Integer Overflow / Rounding Error
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411850203994&w=2
Reference: SECTRACK:1008731
Reference: URL:http://www.securitytracker.com/id?1008731
 

Votes:

   ACCEPT(1) Baker
   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0064

 

Description:
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040113 SuSE linux 9.0 YaST config Skribt [exploit]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107402658600437&w=2
Reference: BID:9411
Reference: URL:http://www.securityfocus.com/bid/9411
Reference: OSVDB:3460
Reference: URL:http://www.osvdb.org/3460
Reference: SECTRACK:1008703
Reference: URL:http://www.securitytracker.com/id?1008703
Reference: SECUNIA:10623
Reference: URL:http://secunia.com/advisories/10623
 

Votes:

   ACCEPT(2) Baker, Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0065

 

Description:
Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040112 More phpGedView Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107394912715478&w=2
Reference: BID:11910
Reference: URL:http://www.securityfocus.com/bid/11910
Reference: BID:11925
Reference: URL:http://www.securityfocus.com/bid/11925
 

Votes:

   ACCEPT(4) Williams, Baker, Cole, Armstrong
   NOOP(2) Wall, Cox
Voter Comments:
 
 Williams> http://sourceforge.net/project/showfiles.php?group_id=55456


Name: CVE-2004-0066

 

Description:
phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040112 More phpGedView Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107394912715478&w=2
Reference: OSVDB:3464
Reference: URL:http://www.osvdb.org/3464
Reference: XF:phpgedview-path-disclosure(14215)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14215
 

Votes:

   ACCEPT(3) Williams, Baker, Armstrong
   NOOP(3) Wall, Cole, Cox
Voter Comments:
 
 Williams> http://sourceforge.net/project/showfiles.php?group_id=55456


Name: CVE-2004-0067

 

Description:
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040112 More phpGedView Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107394912715478&w=2
Reference: BUGTRAQ:20070827 PhpGedView login page multiple XSS
Reference: URL:http://www.securityfocus.com/archive/1/archive/1/477881/100/0/threaded
Reference: BID:11868
Reference: URL:http://www.securityfocus.com/bid/11868
Reference: BID:11880
Reference: URL:http://www.securityfocus.com/bid/11880
Reference: BID:11882
Reference: URL:http://www.securityfocus.com/bid/11882
Reference: BID:11888
Reference: URL:http://www.securityfocus.com/bid/11888
Reference: BID:11890
Reference: URL:http://www.securityfocus.com/bid/11890
Reference: BID:11891
Reference: URL:http://www.securityfocus.com/bid/11891
Reference: BID:11894
Reference: URL:http://www.securityfocus.com/bid/11894
Reference: BID:11903
Reference: URL:http://www.securityfocus.com/bid/11903
Reference: BID:11904
Reference: URL:http://www.securityfocus.com/bid/11904
Reference: BID:11905
Reference: URL:http://www.securityfocus.com/bid/11905
Reference: BID:11906
Reference: URL:http://www.securityfocus.com/bid/11906
Reference: BID:11907
Reference: URL:http://www.securityfocus.com/bid/11907
Reference: FRSIRT:ADV-2007-2995
Reference: URL:http://www.frsirt.com/english/advisories/2007/2995
Reference: OSVDB:3473
Reference: URL:http://www.osvdb.org/3473
Reference: OSVDB:3474
Reference: URL:http://www.osvdb.org/3474
Reference: OSVDB:3475
Reference: URL:http://www.osvdb.org/3475
Reference: OSVDB:3476
Reference: URL:http://www.osvdb.org/3476
Reference: OSVDB:3477
Reference: URL:http://www.osvdb.org/3477
Reference: OSVDB:3478
Reference: URL:http://www.osvdb.org/3478
Reference: SECTRACK:1018613
Reference: URL:http://securitytracker.com/id?1018613
Reference: SECUNIA:26628
Reference: URL:http://secunia.com/advisories/26628
Reference: XF:phpgedview-login-xss(36285)
Reference: URL:http://xforce.iss.net/xforce/xfdb/36285
Reference: XF:phpgedview-multiple-xss(14212)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14212
 

Votes:

   ACCEPT(3) Williams, Baker, Armstrong
   NOOP(3) Wall, Cole, Cox
Voter Comments:
 
 Williams> http://sourceforge.net/project/showfiles.php?group_id=55456


Name: CVE-2004-0069

 

Description:
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040108 Windows FTP Server Format String Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107367110805273&w=2
Reference: BUGTRAQ:20040113 exploit for HD Soft Windows FTP Server 1.6
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107401398014761&w=2
Reference: BID:9385
Reference: URL:http://www.securityfocus.com/bid/9385
Reference: SECTRACK:1008658
Reference: URL:http://www.securitytracker.com/id?1008658
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(3) Williams, Cole, Cox
   REVIEWING(1) Wall
Voter Comments:
 
 Williams> insufficient data.
 Armstrong> Add reference: http://www.securiteam.com/exploits/5TP0C1FBPS.html


Name: CVE-2004-0071

 

Description:
Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040110 PHP Manpage lookup directory transversal / file disclosing
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107392764118403&w=2
Reference: BID:9395
Reference: URL:http://www.securityfocus.com/bid/9395
Reference: SECTRACK:1008689
Reference: URL:http://www.securitytracker.com/id?1008689
Reference: XF:manpagelookup-directory-traversal(14203)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14203
 

Votes:

   ACCEPT(2) Baker, Armstrong
   MODIFY(1) Williams
   NOOP(3) Wall, Cole, Cox
Voter Comments:
 
 Williams> contacted vendor.  affects v1.2.0.  fixed in v1.3.0.
   http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php
   http://php.amnuts.com/forums/viewtopic.php?t=70


Name: CVE-2004-0072

 

Description:
Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040109 Directory Traversal in Accipiter Direct Server 6.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107392576215418&w=2
Reference: FULLDISC:20040109 Directory Traversal in Accipiter Direct Server 6.0
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0274.html
Reference: OSVDB:3433
Reference: URL:http://www.osvdb.org/3433
Reference: SECUNIA:10600
Reference: URL:http://secunia.com/advisories/10600
Reference: XF:accipterdirectserver-directory-traversal(14198)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14198
Reference: BID:9389
Reference: URL:http://www.securityfocus.com/bid/9389
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
 
 Williams> insufficient data.


Name: CVE-2004-0073

 

Description:
PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.

Status: Candidate
Phase: Modified (20060907)
Reference: BUGTRAQ:20040102 include() vuln in EasyDynamicPages v.2.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107307457327707&w=2
Reference: BID:9338
Reference: URL:http://www.securityfocus.com/bid/9338
Reference: OSVDB:3318
Reference: URL:http://www.osvdb.org/3318
Reference: OSVDB:3408
Reference: URL:http://www.osvdb.org/3408
Reference: SECTRACK:1008584
Reference: URL:http://securitytracker.com/id?1008584
Reference: SECUNIA:10535
Reference: URL:http://secunia.com/advisories/10535
Reference: XF:easydynamicpages-php-file-include(14136)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14136
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(4) Williams, Wall, Cole, Cox
Voter Comments:
 
 Williams> insufficient data.


Name: CVE-2004-0074

 

Description:
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040102 xsok local games exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107307407027259&w=2
Reference: BUGTRAQ:20040103 xsok local games exploit (2)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107332542918529&w=2
Reference: BID:9352
Reference: URL:http://www.securityfocus.com/bid/9352
Reference: BID:9341
Reference: URL:http://www.securityfocus.com/bid/9341
Reference: XF:xsok-lang-bo(14910)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14910
Reference: XF:xsok-long-xsokdir-bo(14906)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14906
 

Votes:

   ACCEPT(3) Williams, Baker, Armstrong
   NOOP(3) Wall, Cole, Cox
Voter Comments:
 
 Williams> DSA-405-1


Name: CVE-2004-0076

 

Description:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was removed from consideration by its Candidate Numbering Authority. Notes: none.

Status: Candidate
Phase: Assigned (20040119)
 

Votes:

 

Name: CVE-2004-0079

 

Description:
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

Status: Candidate
Phase: Assigned (20040119)
Reference: BUGTRAQ:20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107953412903636&w=2
Reference: CONFIRM:http://www.openssl.org/news/secadv_20040317.txt
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/224012/index.htm
Reference: CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2005-239.htm
Reference: CISCO:20040317 Cisco OpenSSL Implementation Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
Reference: APPLE:APPLE-SA-2005-08-15
Reference: URL:http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
Reference: APPLE:APPLE-SA-2005-08-17
Reference: URL:http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
Reference: CONECTIVA:CLA-2004:834
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
Reference: DEBIAN:DSA-465
Reference: URL:http://www.debian.org/security/2004/dsa-465
Reference: ENGARDE:ESA-20040317-003
Reference: URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html
Reference: FEDORA:FEDORA-2004-095
Reference: URL:http://fedoranews.org/updates/FEDORA-2004-095.shtml
Reference: FEDORA:FEDORA-2005-1042
Reference: URL:http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00087.html
Reference: FREEBSD:FreeBSD-SA-04:05
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:05.openssl.asc
Reference: GENTOO:GLSA-200403-03
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-03.xml
Reference: HP:SSRT4717
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403806509920&w=2
Reference: MANDRAKE:MDKSA-2004:023
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:023
Reference: NETBSD:NetBSD-SA2004-005
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc
Reference: REDHAT:RHSA-2004:120
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-120.html
Reference: REDHAT:RHSA-2004:121
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-121.html
Reference: REDHAT:RHSA-2004:139
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-139.html
Reference: REDHAT:RHSA-2005:830
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-830.html
Reference: REDHAT:RHSA-2005:829
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-829.html
Reference: SCO:SCOSA-2004.10
Reference: URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt
Reference: SLACKWARE:SSA:2004-077
Reference: URL:http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961
Reference: SUSE:SuSE-SA:2004:007
Reference: URL:http://www.novell.com/linux/security/advisories/2004_07_openssl.html
Reference: SUNALERT:57524
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
Reference: TRUSTIX:2004-0012
Reference: URL:http://www.trustix.org/errata/2004/0012
Reference: CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference: CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00045.html
Reference: CERT:TA04-078A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-078A.html
Reference: CERT-VN:VU#288574
Reference: URL:http://www.kb.cert.org/vuls/id/288574
Reference: CIAC:O-101
Reference: URL:http://www.ciac.org/ciac/bulletins/o-101.shtml
Reference: BID:9899
Reference: URL:http://www.securityfocus.com/bid/9899
Reference: OVAL:oval:org.mitre.oval:def:2621
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2621
Reference: OVAL:oval:org.mitre.oval:def:870
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:870
Reference: OVAL:oval:org.mitre.oval:def:975
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:975
Reference: SECUNIA:11139
Reference: URL:http://secunia.com/advisories/11139
Reference: SECUNIA:17401
Reference: URL:http://secunia.com/advisories/17401
Reference: SECUNIA:17381
Reference: URL:http://secunia.com/advisories/17381
Reference: SECUNIA:17398
Reference: URL:http://secunia.com/advisories/17398
Reference: SECUNIA:18247
Reference: URL:http://secunia.com/advisories/18247
Reference: XF:openssl-dochangecipherspec-dos(15505)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15505
 

Votes:

 

Name: CVE-2004-0081

 

Description:
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

Status: Candidate
Phase: Assigned (20040119)
Reference: BUGTRAQ:20040317 Re: New OpenSSL releases fix denial of service attacks [17 March 2004]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107955049331965&w=2
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/224012/index.htm
Reference: CISCO:20040317 Cisco OpenSSL Implementation Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
Reference: CONECTIVA:CLA-2004:834
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
Reference: DEBIAN:DSA-465
Reference: URL:http://www.debian.org/security/2004/dsa-465
Reference: ENGARDE:ESA-20040317-003
Reference: URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html
Reference: FEDORA:FEDORA-2004-095
Reference: URL:http://fedoranews.org/updates/FEDORA-2004-095.shtml
Reference: GENTOO:GLSA-200403-03
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-03.xml
Reference: REDHAT:RHSA-2004:119
Reference: URL:http://rhn.redhat.com/errata/RHSA-2004-119.html
Reference: REDHAT:RHSA-2004:120
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-120.html
Reference: REDHAT:RHSA-2004:121
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-121.html
Reference: REDHAT:RHSA-2004:139
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-139.html
Reference: SCO:SCOSA-2004.10
Reference: URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt
Reference: SGI:20040304-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040304-01-U.asc
Reference: SUNALERT:57524
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
Reference: TRUSTIX:2004-0012
Reference: URL:http://www.trustix.org/errata/2004/0012
Reference: BUGTRAQ:20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403850228012&w=2
Reference: CERT:TA04-078A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-078A.html
Reference: CERT-VN:VU#465542
Reference: URL:http://www.kb.cert.org/vuls/id/465542
Reference: BID:9899
Reference: URL:http://www.securityfocus.com/bid/9899
Reference: OVAL:oval:org.mitre.oval:def:871
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:871
Reference: OVAL:oval:org.mitre.oval:def:902
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:902
Reference: SECUNIA:11139
Reference: URL:http://secunia.com/advisories/11139
Reference: XF:openssl-tls-dos(15509)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15509
 

Votes:

 

Name: CVE-2004-0083

 

Description:
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

Status: Candidate
Phase: Modified (20061101)
Reference: BUGTRAQ:20040210 iDEFENSESecurityAdvisory02.10.04: XFree86FontInformationFileBufferOverflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107644835523678&w=2
Reference: MISC:http://www.idefense.com/application/poi/display?id=72
Reference: BUGTRAQ:20040211 XFree86 vulnerability exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107653324115914&w=2
Reference: CONFIRM:http://www.xfree86.org/cvs/changes
Reference: CONECTIVA:CLA-2004:821
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000821
Reference: DEBIAN:DSA-443
Reference: URL:http://www.debian.org/security/2004/dsa-443
Reference: FEDORA:FLSA:2314
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110979666528890&w=2
Reference: REDHAT:RHSA-2004:059
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-059.html
Reference: REDHAT:RHSA-2004:060
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-060.html
Reference: REDHAT:RHSA-2004:061
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-061.html
Reference: SLACKWARE:SSA:2004-043
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
Reference: SUNALERT:57768
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1
Reference: SUSE:SuSE-SA:2004:006
Reference: URL:http://www.novell.com/linux/security/advisories/2004_06_xf86.html
Reference: MANDRAKE:MDKSA-2004:012
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:012
Reference: GENTOO:GLSA-200402-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200402-02.xml
Reference: CERT-VN:VU#820006
Reference: URL:http://www.kb.cert.org/vuls/id/820006
Reference: BID:9636
Reference: URL:http://www.securityfocus.com/bid/9636
Reference: OVAL:oval:org.mitre.oval:def:806
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:806
Reference: OVAL:oval:org.mitre.oval:def:830
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:830
Reference: XF:xfree86-fontalias-bo(15130)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15130
 

Votes:

   ACCEPT(5) Wall, Baker, Cole, Armstrong, Cox
   NOOP(1) Christey
Voter Comments:
 
 Christey> CIAC:O-081
   URL:http://www.ciac.org/ciac/bulletins/o-081.shtml
   IMMUNIX:IMNX-2004-73-002-01
   URL:http://www.securityfocus.com/advisories/6328
   BID:9636
   URL:http://www.securityfocus.com/bid/9636
 Christey> Normalize Gentoo reference
 Christey> SCO:SCOSA-2004.2
   URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt
   SCO:SCOSA-2004.3
   URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt


Name: CVE-2004-0084

 

Description:
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

Status: Candidate
Phase: Modified (20061101)
Reference: BUGTRAQ:20040212 iDEFENSE Security Advisory 02.11.04: XFree86 Font Information File Buffer Overflow II
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107662833512775&w=2
Reference: MISC:http://www.idefense.com/application/poi/display?id=73
Reference: CONECTIVA:CLA-2004:821
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000821
Reference: DEBIAN:DSA-443
Reference: URL:http://www.debian.org/security/2004/dsa-443
Reference: FEDORA:FLSA:2314
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110979666528890&w=2
Reference: REDHAT:RHSA-2004:059
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-059.html
Reference: REDHAT:RHSA-2004:060
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-060.html
Reference: REDHAT:RHSA-2004:061
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-061.html
Reference: SLACKWARE:SSA:2004-043
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
Reference: SUNALERT:57768
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57768-1
Reference: SUSE:SuSE-SA:2004:006
Reference: URL:http://www.novell.com/linux/security/advisories/2004_06_xf86.html
Reference: MANDRAKE:MDKSA-2004:012
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:012
Reference: CERT-VN:VU#667502
Reference: URL:http://www.kb.cert.org/vuls/id/667502
Reference: BID:9652
Reference: URL:http://www.securityfocus.com/bid/9652
Reference: OVAL:oval:org.mitre.oval:def:807
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:807
Reference: OVAL:oval:org.mitre.oval:def:831
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:831
Reference: XF:xfree86-copyisolatin1lLowered-bo(15200)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15200
 

Votes:

   ACCEPT(3) Baker, Armstrong, Cox
   NOOP(2) Christey, Cole
   REVIEWING(1) Wall
Voter Comments:
 
 Christey> CIAC:O-081
   URL:http://www.ciac.org/ciac/bulletins/o-081.shtml
   IMMUNIX:IMNX-2004-73-002-01
   URL:http://www.securityfocus.com/advisories/6328
   BID:9652
   URL:http://www.securityfocus.com/bid/9652
 Christey> SCO:SCOSA-2004.2
   URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt
   SCO:SCOSA-2004.3
   URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt


Name: CVE-2004-0085

 

Description:
Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.

Status: Candidate
Phase: Modified (20050813)
Reference: APPLE:APPLE-SA-2004-01-26
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference: URL:http://www.securityfocus.com/bid/9504
Reference: XF:macosx-mail-undisclosed(14992)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14992
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0086

 

Description:
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.

Status: Candidate
Phase: Modified (20050813)
Reference: APPLE:APPLE-SA-2004-01-26
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference: URL:http://www.securityfocus.com/bid/9504
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0087

 

Description:
The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.

Status: Candidate
Phase: Modified (20071113)
Reference: APPLE:APPLE-SA-2004-01-26
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference: URL:http://www.securityfocus.com/bid/9504
Reference: OSVDB:6819
Reference: URL:http://www.osvdb.org/6819
Reference: XF:macosx-configd-file-manipulation(14997)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14997
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0088

 

Description:
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.

Status: Candidate
Phase: Modified (20071113)
Reference: APPLE:APPLE-SA-2004-01-26
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference: URL:http://www.securityfocus.com/bid/9504
Reference: OSVDB:6820
Reference: URL:http://www.osvdb.org/6820
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0090

 

Description:
Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.

Status: Candidate
Phase: Assigned (20040120)
Reference: APPLE:APPLE-SA-2004-01-26
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: AUSCERT:ESB-2004.0072
Reference: URL:http://www.auscert.org.au/render.html?it=3791&cid=1
Reference: BID:9504
Reference: URL:http://www.securityfocus.com/bid/9504
Reference: SECUNIA:10723
Reference: URL:http://secunia.com/advisories/10723/
 

Votes:

 

Name: CVE-2004-0091

 

Description:
** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."

Status: Candidate
Phase: Modified (20051208)
Reference: BUGTRAQ:20040120 vBulletin Security Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107462349324945&w=2
Reference: VULN-DEV:20040120 vBulletin Security Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=107462499927040&w=2
Reference: VULN-DEV:20040120 Re: vBulletin Security Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=107478592401619&w=2
Reference: VULN-DEV:20040123 RE: vBulletin Security Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=107488880317647&w=2
Reference: SECTRACK:1008780
Reference: URL:http://securitytracker.com/id?1008780
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox
   REVIEWING(1) Green

Name: CVE-2004-0092

 

Description:
Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.

Status: Candidate
Phase: Modified (20040812)
Reference: APPLE:APPLE-SA-2004-01-26
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Jan/msg00000.html
Reference: BID:9504
Reference: URL:http://www.securityfocus.com/bid/9504
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0097

 

Description:
Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

Status: Candidate
Phase: Modified (20071113)
Reference: DEBIAN:DSA-448
Reference: URL:http://www.debian.org/security/2004/dsa-448
Reference: REDHAT:RHSA-2004:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-047.html
Reference: CERT:CA-2004-01
Reference: URL:http://www.cert.org/advisories/CA-2004-01.html
Reference: CERT-VN:VU#749342
Reference: URL:http://www.kb.cert.org/vuls/id/749342
Reference: BID:9406
Reference: URL:http://www.securityfocus.com/bid/9406
Reference: XF:pwlib-message-dos(15202)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15202
Reference: OVAL:oval:org.mitre.oval:def:803
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:803
Reference: OVAL:oval:org.mitre.oval:def:826
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:826
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   MODIFY(1) Cox
   NOOP(1) Christey
Voter Comments:
 
 Cox> Addref: REDHAT:RHSA-2004:048
   Be useful to mention OpenH323 and/or H.323 in this text to aid
   searching on this issue
 Christey> BUGTRAQ:20040409 [ GLSA 200404-11 ] Multiple Vulnerabilities in pwlib


Name: CVE-2004-0098

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040128)
 

Votes:

 

Name: CVE-2004-0100

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040129)
 

Votes:

 

Name: CVE-2004-0101

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040129)
 

Votes:

 

Name: CVE-2004-0102

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040129)
 

Votes:

 

Name: CVE-2004-0103

 

Description:
crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.

Status: Candidate
Phase: Modified (20050808)
Reference: DEBIAN:DSA-432
Reference: URL:http://www.debian.org/security/2004/dsa-432
Reference: BID:9566
Reference: URL:http://www.securityfocus.com/bid/9566
Reference: SECUNIA:10788
Reference: URL:http://secunia.com/advisories/10788/
Reference: XF:crawl-long-environment-bo(15032)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15032
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0104

 

Description:
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

Status: Candidate
Phase: Modified (20050808)
Reference: BUGTRAQ:20040218 metamail format string bugs and buffer overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107713476911429&w=2
Reference: VULNWATCH:20040218 metamail format string bugs and buffer overflows
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html
Reference: DEBIAN:DSA-449
Reference: URL:http://www.debian.org/security/2004/dsa-449
Reference: MANDRAKE:MDKSA-2004:014
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:014
Reference: REDHAT:RHSA-2004:073
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-073.html
Reference: SLACKWARE:SSA:2004-049
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404734
Reference: CERT-VN:VU#518518
Reference: URL:http://www.kb.cert.org/vuls/id/518518
Reference: CIAC:O-083
Reference: URL:http://www.ciac.org/ciac/bulletins/o-083.shtml
Reference: BID:9692
Reference: URL:http://www.securityfocus.com/bid/9692
Reference: SECUNIA:10908
Reference: URL:http://secunia.com/advisories/10908
Reference: XF:metamail-contenttype-format-string(15245)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15245
Reference: XF:metamail-printheader-format-string(15259)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15259
 

Votes:

   ACCEPT(5) Wall, Baker, Cole, Armstrong, Cox

Name: CVE-2004-0105

 

Description:
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

Status: Candidate
Phase: Modified (20050808)
Reference: BUGTRAQ:20040218 metamail format string bugs and buffer overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107713476911429&w=2
Reference: VULNWATCH:20040218 metamail format string bugs and buffer overflows
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0041.html
Reference: DEBIAN:DSA-449
Reference: URL:http://www.debian.org/security/2004/dsa-449
Reference: MANDRAKE:MDKSA-2004:014
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:014
Reference: REDHAT:RHSA-2004:073
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-073.html
Reference: SLACKWARE:SSA:2004-049
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404734
Reference: CERT-VN:VU#513062
Reference: URL:http://www.kb.cert.org/vuls/id/513062
Reference: CIAC:O-083
Reference: URL:http://www.ciac.org/ciac/bulletins/o-083.shtml
Reference: BID:9692
Reference: URL:http://www.securityfocus.com/bid/9692
Reference: SECUNIA:10908
Reference: URL:http://secunia.com/advisories/10908
Reference: XF:metamail-printheader-nonascii-bo(15247)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15247
Reference: XF:metamail-splitmail-subject-bo(15258)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15258
 

Votes:

   ACCEPT(5) Wall, Baker, Cole, Armstrong, Cox

Name: CVE-2004-0106

 

Description:
Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.

Status: Candidate
Phase: Modified (20061101)
Reference: CONECTIVA:CLA-2004:821
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000821
Reference: DEBIAN:DSA-443
Reference: URL:http://www.debian.org/security/2004/dsa-443
Reference: FEDORA:FLSA:2314
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110979666528890&w=2
Reference: REDHAT:RHSA-2004:059
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-059.html
Reference: REDHAT:RHSA-2004:060
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-060.html
Reference: REDHAT:RHSA-2004:061
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-061.html
Reference: SLACKWARE:SSA:2004-043
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.405053
Reference: SUSE:SuSE-SA:2004:006
Reference: URL:http://www.novell.com/linux/security/advisories/2004_06_xf86.html
Reference: MANDRAKE:MDKSA-2004:012
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:012
Reference: XF:xfree86-multiple-font-improper-handling(15206)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15206
Reference: OVAL:oval:org.mitre.oval:def:809
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:809
Reference: OVAL:oval:org.mitre.oval:def:832
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:832
 

Votes:

   ACCEPT(3) Baker, Armstrong, Cox
   NOOP(2) Christey, Cole
   REVIEWING(1) Wall
Voter Comments:
 
 Christey> CIAC:O-081
   URL:http://www.ciac.org/ciac/bulletins/o-081.shtml
   IMMUNIX:IMNX-2004-73-002-01
   URL:http://www.securityfocus.com/advisories/6328
   BID:9655
   URL:http://www.securityfocus.com/bid/9655
   TURBO:TLSA-2004-5
   URL:http://www.turbolinux.com/security/2004/TLSA-2004-5.txt
 Christey> SCO:SCOSA-2004.2
   URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt
   SCO:SCOSA-2004.3
   URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt


Name: CVE-2004-0107

 

Description:
The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.

Status: Candidate
Phase: Modified (20061101)
Reference: REDHAT:RHSA-2004:053
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-053.html
Reference: REDHAT:RHSA-2004:093
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-093.html
Reference: SGI:20040302-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040302-01-U.asc
Reference: CIAC:O-097
Reference: URL:http://www.ciac.org/ciac/bulletins/o-097.shtml
Reference: BID:9838
Reference: URL:http://www.securityfocus.com/bid/9838
Reference: OSVDB:6884
Reference: URL:http://www.osvdb.org/6884
Reference: OVAL:oval:org.mitre.oval:def:849
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:849
Reference: OVAL:oval:org.mitre.oval:def:862
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:862
Reference: XF:sysstat-post-trigger-symlink(15428)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15428
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   MODIFY(2) Frech, Cox
   NOOP(1) Christey
Voter Comments:
 
 Frech> XF:sysstat-post-trigger-symlink(15428)
   http://xforce.iss.net/xforce/xfdb/15428
 Cox> This issue is in the vendor packaging of sysstat, not sysstat itself,
   and does not apply to a particular version of upstream
   sysstat. Suggest "trigger scripts in various vendors packaging of
   syssstat allows local users..." or "in the Red Hat packaging of sysstat"
 Christey> CIAC:O-097
   URL:http://www.ciac.org/ciac/bulletins/o-097.shtml
   XF:sysstat-post-trigger-symlink(15428)
   URL:http://xforce.iss.net/xforce/xfdb/15428
   BID:9838
   URL:http://www.securityfocus.com/bid/9838
 Christey> FEDORA:FEDORA-2004-1372
   URL:https://bugzilla.fedora.us/show_bug.cgi?id=1372


Name: CVE-2004-0109

 

Description:
Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.

Status: Candidate
Phase: Assigned (20040202)
Reference: MISC:http://www.idefense.com/application/poi/display?id=101&type=vulnerabilities
Reference: CONECTIVA:CLA-2004:846
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-479
Reference: URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference: URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference: URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference: URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference: URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference: URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference: URL:http://www.debian.org/security/2004/dsa-495
Reference: ENGARDE:ESA-20040428-004
Reference: URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:105
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-105.html
Reference: REDHAT:RHSA-2004:106
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-106.html
Reference: REDHAT:RHSA-2004:166
Reference: URL:http://rhn.redhat.com/errata/RHSA-2004-166.html
Reference: REDHAT:RHSA-2004:183
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-183.html
Reference: SGI:20040405-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc
Reference: SGI:20040504-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc
Reference: SUSE:SuSE-SA:2004:009
Reference: URL:http://www.novell.com/linux/security/advisories/2004_09_kernel.html
Reference: TRUSTIX:2004-0020
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference: TURBO:TLSA-2004-14
Reference: URL:http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
Reference: CIAC:O-121
Reference: URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-127
Reference: URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: BID:10141
Reference: URL:http://www.securityfocus.com/bid/10141
Reference: OVAL:oval:org.mitre.oval:def:940
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940
Reference: SECUNIA:11361
Reference: URL:http://secunia.com/advisories/11361
Reference: SECUNIA:11362
Reference: URL:http://secunia.com/advisories/11362
Reference: SECUNIA:11373
Reference: URL:http://secunia.com/advisories/11373
Reference: SECUNIA:11429
Reference: SECUNIA:11464
Reference: URL:http://secunia.com/advisories/11464
Reference: SECUNIA:11469
Reference: URL:http://secunia.com/advisories/11469
Reference: SECUNIA:11470
Reference: URL:http://secunia.com/advisories/11470
Reference: SECUNIA:11486
Reference: URL:http://secunia.com/advisories/11486
Reference: SECUNIA:11494
Reference: URL:http://secunia.com/advisories/11494
Reference: SECUNIA:11518
Reference: URL:http://secunia.com/advisories/11518
Reference: SECUNIA:11626
Reference: URL:http://secunia.com/advisories/11626
Reference: SECUNIA:11861
Reference: URL:http://secunia.com/advisories/11861
Reference: SECUNIA:11891
Reference: URL:http://secunia.com/advisories/11891
Reference: SECUNIA:11986
Reference: URL:http://secunia.com/advisories/11986
Reference: SECUNIA:12003
Reference: URL:http://secunia.com/advisories/12003
Reference: XF:linux-iso9660-bo(15866)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15866
 

Votes:

 

Name: CVE-2004-0110

 

Description:
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.

Status: Candidate
Phase: Modified (20070303)
Reference: CONFIRM:http://www.xmlsoft.org/news.html
Reference: DEBIAN:DSA-455
Reference: URL:http://www.debian.org/security/2004/dsa-455
Reference: GENTOO:GLSA-200403-01
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-01.xml
Reference: REDHAT:RHSA-2004:090
Reference: URL:http://rhn.redhat.com/errata/RHSA-2004-090.html
Reference: REDHAT:RHSA-2004:091
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-091.html
Reference: BUGTRAQ:20040305 [OpenPKG-SA-2004.003] OpenPKG Security Advisory (libxml)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107851606605420&w=2
Reference: BUGTRAQ:20040306 TSLSA-2004-0010 - libxml2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107860178228804&w=2
Reference: REDHAT:RHSA-2004:650
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-650.html
Reference: SUSE:SUSE-SR:2005:001
Reference: URL:http://www.novell.com/linux/security/advisories/2005_01_sr.html
Reference: CERT-VN:VU#493966
Reference: URL:http://www.kb.cert.org/vuls/id/493966
Reference: CIAC:O-086
Reference: URL:http://www.ciac.org/ciac/bulletins/o-086.shtml
Reference: BID:9718
Reference: URL:http://www.securityfocus.com/bid/9718
Reference: SECUNIA:10958
Reference: URL:http://secunia.com/advisories/10958/
Reference: OVAL:oval:org.mitre.oval:def:833
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:833
Reference: OVAL:oval:org.mitre.oval:def:875
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:875
Reference: XF:libxml2-nanohttp-bo(15301)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15301
Reference: XF:libxml2-nanoftp-bo(15302)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15302
 

Votes:

   ACCEPT(6) Green, Wall, Baker, Cole, Armstrong, Cox
   NOOP(1) Christey
Voter Comments:
 
 Christey> CONECTIVA:CLA-2004:836
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000836
 Christey> Add APPLE-SA-2004-04-05
   CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00047.html
 Green> VERIFIED-BY-SOMEONE-I-TRUST
 Christey> Normalize Trustix references
 Christey> FEDORA:FEDORA-2004-1324
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109035140702164&w=2


Name: CVE-2004-0112

 

Description:
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

Status: Candidate
Phase: Assigned (20040202)
Reference: BUGTRAQ:20040317 New OpenSSL releases fix denial of service attacks [17 March 2004]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107953412903636&w=2
Reference: CONFIRM:http://www.openssl.org/news/secadv_20040317.txt
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/224012/index.htm
Reference: APPLE:APPLE-SA-2005-08-15
Reference: URL:http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
Reference: APPLE:APPLE-SA-2005-08-17
Reference: URL:http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
Reference: CISCO:20040317 Cisco OpenSSL Implementation Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
Reference: CONECTIVA:CLA-2004:834
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000834
Reference: GENTOO:GLSA-200403-03
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-03.xml
Reference: MANDRAKE:MDKSA-2004:023
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:023
Reference: NETBSD:NetBSD-SA2004-005
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-005.txt.asc
Reference: REDHAT:RHSA-2004:120
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-120.html
Reference: REDHAT:RHSA-2004:121
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-121.html
Reference: SCO:SCOSA-2004.10
Reference: URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.10/SCOSA-2004.10.txt
Reference: SLACKWARE:SSA:2004-077
Reference: URL:http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.455961
Reference: SUSE:SuSE-SA:2004:007
Reference: URL:http://www.novell.com/linux/security/advisories/2004_07_openssl.html
Reference: SUNALERT:57524
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57524
Reference: TRUSTIX:2004-0012
Reference: URL:http://www.trustix.org/errata/2004/0012
Reference: HP:SSRT4717
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403806509920&w=2
Reference: CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference: CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00045.html
Reference: CERT:TA04-078A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-078A.html
Reference: CERT-VN:VU#484726
Reference: URL:http://www.kb.cert.org/vuls/id/484726
Reference: CIAC:O-101
Reference: URL:http://www.ciac.org/ciac/bulletins/o-101.shtml
Reference: BID:9899
Reference: URL:http://www.securityfocus.com/bid/9899
Reference: OVAL:oval:org.mitre.oval:def:1049
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1049
Reference: OVAL:oval:org.mitre.oval:def:928
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:928
Reference: SECUNIA:11139
Reference: URL:http://secunia.com/advisories/11139
Reference: XF:openssl-kerberos-ciphersuites-dos(15508)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15508
 

Votes:

 

Name: CVE-2004-0116

 

Description:
An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.

Status: Candidate
Phase: Assigned (20040203)
Reference: EEYE:AD20040413A
Reference: URL:http://www.eeye.com/html/Research/Advisories/AD20040413A.html
Reference: MS:MS04-012
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-012.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#417052
Reference: URL:http://www.kb.cert.org/vuls/id/417052
Reference: CIAC:O-115
Reference: URL:http://www.ciac.org/ciac/bulletins/o-115.shtml
Reference: BID:10127
Reference: URL:http://www.securityfocus.com/bid/10127
Reference: OVAL:oval:org.mitre.oval:def:955
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:955
Reference: OVAL:oval:org.mitre.oval:def:957
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:957
Reference: OVAL:oval:org.mitre.oval:def:958
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:958
Reference: SECTRACK:1009758
Reference: URL:http://securitytracker.com/alerts/2004/Apr/1009758.html
Reference: SECUNIA:11065
Reference: URL:http://secunia.com/advisories/11065/
Reference: XF:win-rpcss-rpcmessage-dos(15708)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15708
 

Votes:

 

Name: CVE-2004-0117

 

Description:
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-011
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#353956
Reference: URL:http://www.kb.cert.org/vuls/id/353956
Reference: CIAC:O-114
Reference: URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: OVAL:oval:org.mitre.oval:def:907
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:907
Reference: OVAL:oval:org.mitre.oval:def:946
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:946
Reference: OVAL:oval:org.mitre.oval:def:964
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:964
Reference: XF:win-h323-bo(15710)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15710
 

Votes:

 

Name: CVE-2004-0118

 

Description:
The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.

Status: Candidate
Phase: Assigned (20040203)
Reference: FULLDISC:20040413 EEYE: Windows VDM TIB Local Privilege Escalation
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html
Reference: EEYE:AD20040413E
Reference: URL:http://www.eeye.com/html/Research/Advisories/AD20040413E.html
Reference: MS:MS04-011
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#783748
Reference: URL:http://www.kb.cert.org/vuls/id/783748
Reference: CIAC:O-114
Reference: URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10117
Reference: URL:http://www.securityfocus.com/bid/10117
Reference: OVAL:oval:org.mitre.oval:def:1512
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1512
Reference: OVAL:oval:org.mitre.oval:def:1718
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1718
Reference: XF:win-vdm-gain-privileges(15714)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15714
 

Votes:

 

Name: CVE-2004-0119

 

Description:
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.

Status: Candidate
Phase: Assigned (20040203)
Reference: VULNWATCH:20040414 NSFOCUS SA2004-01 : DoS Vulnerability in Microsoft Windows SPNEGO Protocol Decoding
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html
Reference: MS:MS04-011
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#638548
Reference: URL:http://www.kb.cert.org/vuls/id/638548
Reference: CIAC:O-114
Reference: URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10113
Reference: URL:http://www.securityfocus.com/bid/10113
Reference: OVAL:oval:org.mitre.oval:def:1808
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1808
Reference: OVAL:oval:org.mitre.oval:def:1962
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1962
Reference: OVAL:oval:org.mitre.oval:def:1997
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1997
Reference: XF:win-spp-bo(15715)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15715
 

Votes:

 

Name: CVE-2004-0120

 

Description:
The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.

Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-011
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#150236
Reference: URL:http://www.kb.cert.org/vuls/id/150236
Reference: CIAC:O-114
Reference: URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10115
Reference: URL:http://www.securityfocus.com/bid/10115
Reference: OVAL:oval:org.mitre.oval:def:885
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:885
Reference: OVAL:oval:org.mitre.oval:def:886
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:886
Reference: OVAL:oval:org.mitre.oval:def:892
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:892
Reference: XF:ssl-message-dos(15712)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15712
 

Votes:

 

Name: CVE-2004-0123

 

Description:
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-011
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-011.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#255924
Reference: URL:http://www.kb.cert.org/vuls/id/255924
Reference: CIAC:O-114
Reference: URL:http://www.ciac.org/ciac/bulletins/o-114.shtml
Reference: BID:10118
Reference: URL:http://www.securityfocus.com/bid/10118
Reference: OVAL:oval:org.mitre.oval:def:1007
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1007
Reference: OVAL:oval:org.mitre.oval:def:1076
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1076
Reference: OVAL:oval:org.mitre.oval:def:924
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:924
Reference: XF:win-asn1-double-free(15713)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15713
 

Votes:

 

Name: CVE-2004-0124

 

Description:
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."

Status: Candidate
Phase: Assigned (20040203)
Reference: MS:MS04-012
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-012.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#212892
Reference: URL:http://www.kb.cert.org/vuls/id/212892
Reference: CIAC:O-115
Reference: URL:http://www.ciac.org/ciac/bulletins/o-115.shtml
Reference: BID:10121
Reference: URL:http://www.securityfocus.com/bid/10121
Reference: OVAL:oval:org.mitre.oval:def:1041
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1041
Reference: OVAL:oval:org.mitre.oval:def:1062
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1062
Reference: OVAL:oval:org.mitre.oval:def:1066
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1066
Reference: OVAL:oval:org.mitre.oval:def:1072
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1072
Reference: SECUNIA:11065
Reference: URL:http://secunia.com/advisories/11065/
Reference: XF:win-objectidentifier-open-port(15711)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15711
 

Votes:

 

Name: CVE-2004-0125

 

Description:
The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table.

Status: Candidate
Phase: Assigned (20040203)
Reference: FREEBSD:FreeBSD-SA-04:12
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:12.jailroute.asc
Reference: BID:10485
Reference: URL:http://www.securityfocus.com/bid/10485
Reference: XF:freebsd-jailed-table-modify(16342)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16342
 

Votes:

 

Name: CVE-2004-0127

 

Description:
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.

Status: Candidate
Phase: Modified (20071113)
Reference: BUGTRAQ:20040129 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior
Reference: URL:http://www.securityfocus.com/archive/1/352355
Reference: BID:9529
Reference: URL:http://www.securityfocus.com/bid/9529
Reference: OSVDB:3768
Reference: URL:http://www.osvdb.org/displayvuln.php?osvdb_id=3768
Reference: SECTRACK:1008892
Reference: URL:http://www.securitytracker.com/id?1008892
Reference: SECUNIA:10753
Reference: URL:http://secunia.com/advisories/10753/
Reference: XF:phpgedview-editconfig-directory-traversal(15129)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15129
 

Votes:

   ACCEPT(2) Green, Baker
   NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
 
 Green> Vendor ack'ed and provides an update;
   http://prdownloads.sourceforge.net/phpgedview/phpGedView-2.65.2.zip?download


Name: CVE-2004-0130

 

Description:
login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.

Status: Candidate
Phase: Modified (20071113)
Reference: MISC:http://www.netvigilance.com/advisory0001
Reference: MISC:http://www.securiteam.com/unixfocus/5NP0M1PBPQ.html
Reference: OSVDB:6886
Reference: URL:http://www.osvdb.org/6886
Reference: SECTRACK:1008844
Reference: URL:http://securitytracker.com/alerts/2004/Jan/1008844.html
Reference: XF:phpgedview-loginphp-path-disclosure(15128)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15128
 

Votes:

   ACCEPT(2) Green, Baker
   NOOP(4) Wall, Cole, Armstrong, Cox
Voter Comments:
 
 Green> Vendor acknowledges and supplies fix in version version 2.65.2


Name: CVE-2004-0132

 

Description:
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.

Status: Candidate
Phase: Modified (20060907)
Reference: BUGTRAQ:20040210 PHP Code Injection Vulnerabilities in ezContents 2.0.2 and prior
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107651585921958&w=2
Reference: XF:ezcontents-multiple-file-include(15135)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15135
 

Votes:

   ACCEPT(2) Baker, Armstrong
   NOOP(3) Wall, Cole, Cox

Name: CVE-2004-0133

 

Description:
The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.

Status: Candidate
Phase: Assigned (20040211)
Reference: ENGARDE:ESA-20040428-004
Reference: URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: SGI:20040405-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc
Reference: TRUSTIX:2004-0020
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference: BID:10151
Reference: URL:http://www.securityfocus.com/bid/10151
Reference: SECUNIA:11362
Reference: URL:http://secunia.com/advisories/11362
Reference: XF:linux-xfs-info-disclosure(15901)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15901
 

Votes:

 

Name: CVE-2004-0134

 

Description:
cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.

Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040507-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040507-01-P.asc
Reference: BID:10418
Reference: URL:http://www.securityfocus.com/bid/10418
Reference: XF:irix-cpr-gain-privileges(16259)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16259
 

Votes:

 

Name: CVE-2004-0135

 

Description:
The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.

Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040601-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc
Reference: OSVDB:7122
Reference: URL:http://www.osvdb.org/7122
Reference: SECUNIA:11872
Reference: URL:http://secunia.com/advisories/11872
Reference: XF:irix-sgiioprobe-gain-privileges(16413)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16413
 

Votes:

 

Name: CVE-2004-0136

 

Description:
The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary."

Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040601-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc
Reference: OSVDB:7123
Reference: URL:http://www.osvdb.org/7123
Reference: SECUNIA:11872
Reference: URL:http://secunia.com/advisories/11872
Reference: XF:irix-mapelf32exec-dos(16416)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16416
Reference: BID:10547
Reference: URL:http://www.securityfocus.com/bid/10547
 

Votes:

 

Name: CVE-2004-0137

 

Description:
Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues."

Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040601-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040601-01-P.asc
Reference: OSVDB:7124
Reference: URL:http://www.osvdb.org/7124
Reference: SECUNIA:11872
Reference: URL:http://secunia.com/advisories/11872
Reference: XF:irix-page-dos(16417)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16417
Reference: BID:10549
Reference: URL:http://www.securityfocus.com/bid/10549
 

Votes:

 

Name: CVE-2004-0138

 

Description:
The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.

Status: Candidate
Phase: Assigned (20040211)
Reference: CONFIRM:http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes
Reference: CONFIRM:http://linux.bkbits.net:8080/linux-2.4/cset@4021346f79nBb-4X_usRikR3Iyb4Vg
Reference: CONFIRM:http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.25
Reference: DEBIAN:DSA-1070
Reference: URL:http://www.debian.org/security/2006/dsa-1070
Reference: DEBIAN:DSA-1067
Reference: URL:http://www.debian.org/security/2006/dsa-1067
Reference: DEBIAN:DSA-1069
Reference: URL:http://www.debian.org/security/2006/dsa-1069
Reference: DEBIAN:DSA-1082
Reference: URL:http://www.debian.org/security/2006/dsa-1082
Reference: REDHAT:RHSA-2004:549
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-549.html
Reference: REDHAT:RHSA-2004:504
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-504.html
Reference: BID:18174
Reference: URL:http://www.securityfocus.com/bid/18174
Reference: SECUNIA:20162
Reference: URL:http://secunia.com/advisories/20162
Reference: SECUNIA:20163
Reference: URL:http://secunia.com/advisories/20163
Reference: SECUNIA:20202
Reference: URL:http://secunia.com/advisories/20202
Reference: SECUNIA:20338
Reference: URL:http://secunia.com/advisories/20338
Reference: XF:linux-kernel-elfloader-dos(43124)
Reference: URL:http://xforce.iss.net/xforce/xfdb/43124
 

Votes:

 

Name: CVE-2004-0139

 

Description:
Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.

Status: Candidate
Phase: Assigned (20040211)
Reference: SGI:20040905-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040905-01-P.asc
Reference: SECUNIA:12682
Reference: URL:http://secunia.com/advisories/12682
Reference: BID:11276
Reference: URL:http://www.securityfocus.com/bid/11276
Reference: XF:irix-bsda-kernel(17547)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17547
 

Votes:

 

Name: CVE-2004-0140

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040211)
 

Votes:

 

Name: CVE-2004-0141

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040211)
 

Votes:

 

Name: CVE-2004-0142

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040211)
 

Votes:

 

Name: CVE-2004-0143

 

Description:
Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.

Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634788029065&w=2
Reference: VULNWATCH:20040209 ptl-2004-01: Multiple vulnerabilities in Nokia phones
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0034.html
Reference: MISC:http://www.pentest.co.uk/documents/ptl-2004-01.html
Reference: BID:9603
Reference: URL:http://www.securityfocus.com/bid/9603
Reference: XF:nokia-obex-dos(15107)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15107
 

Votes:

   ACCEPT(3) Cole, Armstrong, Cox
   NOOP(1) Wall
Voter Comments:
 
 Armstrong> I believe that Mobile phones, PDAs etc are all valid IT devices and should be included as part of the CVE.


Name: CVE-2004-0144

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040212)
 

Votes:

 

Name: CVE-2004-0145

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040212)
 

Votes:

 

Name: CVE-2004-0146

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040212)
 

Votes:

 

Name: CVE-2004-0147

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040212)
 

Votes:

 

Name: CVE-2004-0149

 

Description:
Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.

Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-451
Reference: URL:http://www.debian.org/security/2004/dsa-451
Reference: BID:9764
Reference: URL:http://www.securityfocus.com/bid/9764
Reference: XF:xboing-bo(15347)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15347
 

Votes:

 

Name: CVE-2004-0151

 

Description:
Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.

Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-462
Reference: URL:http://www.debian.org/security/2004/dsa-462
Reference: MISC:http://shellcode.org/Advisories/XITALK.txt
Reference: SECUNIA:11114
Reference: URL:http://secunia.com/advisories/11114/
Reference: BID:9851
Reference: URL:http://www.securityfocus.com/bid/9851
Reference: XF:xitalk-gain-privileges(15456)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15456
 

Votes:

 

Name: CVE-2004-0152

 

Description:
Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.

Status: Candidate
Phase: Assigned (20040213)
Reference: BUGTRAQ:20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108024939827236&w=2
Reference: DEBIAN:DSA-468
Reference: URL:http://www.debian.org/security/2004/dsa-468
Reference: SUSE:SuSE-SA:2004:008
Reference: XF:emil-email-bo(15601)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15601
 

Votes:

 

Name: CVE-2004-0153

 

Description:
Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.

Status: Candidate
Phase: Assigned (20040213)
Reference: BUGTRAQ:20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108024939827236&w=2
Reference: DEBIAN:DSA-468
Reference: URL:http://www.debian.org/security/2004/dsa-468
Reference: SUSE:SuSE-SA:2004:008
Reference: XF:emil-format-string(15602)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15602
 

Votes:

 

Name: CVE-2004-0154

 

Description:
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.

Status: Candidate
Phase: Assigned (20040213)
Reference: REDHAT:RHSA-2004:072
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-072.html
Reference: TRUSTIX:2004-0009
Reference: URL:http://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt
Reference: MISC:http://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535
Reference: XF:nfs-utils-dns-dos(15418)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15418
Reference: BID:9813
Reference: URL:http://www.securityfocus.com/bid/9813
Reference: OVAL:oval:org.mitre.oval:def:861
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:861
 

Votes:

 

Name: CVE-2004-0155

 

Description:
The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.

Status: Candidate
Phase: Assigned (20040213)
Reference: BUGTRAQ:20040407 CAN-2004-0155: The KAME IKE Daemon Racoon does not verify RSA Signatures during Phase 1, allows man-in-the-middle attacks and unauthorized connections
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108136746911000&w=2
Reference: GENTOO:GLSA-200406-17
Reference: URL:http://www.gentoo.org/security/en/glsa/glsa-200406-17.xml
Reference: MANDRAKE:MDKSA-2004:027
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:027
Reference: MANDRAKE:MDKSA-2004:069
Reference: URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069
Reference: APPLE:APPLE-SA-2004-05-03
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108369640424244&w=2
Reference: REDHAT:RHSA-2004:165
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-165.html
Reference: SCO:SCOSA-2005.10
Reference: URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
Reference: CERT-VN:VU#552398
Reference: URL:http://www.kb.cert.org/vuls/id/552398
Reference: OVAL:oval:org.mitre.oval:def:945
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:945
Reference: SECUNIA:11328
Reference: URL:http://secunia.com/advisories/11328
 

Votes:

 

Name: CVE-2004-0156

 

Description:
Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.

Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-485
Reference: URL:http://www.debian.org/security/2004/dsa-485
Reference: GENTOO:GLSA-200404-18
Reference: URL:http://security.gentoo.org/glsa/glsa-200404-18.xml
Reference: BUGTRAQ:20040507 [OpenPKG-SA-2004.020] OpenPKG Security Advisory (ssmtp)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108403772130855&w=2
Reference: BID:10150
Reference: URL:http://www.securityfocus.com/bid/10150
Reference: OSVDB:5360
Reference: URL:http://www.osvdb.org/5360
Reference: OSVDB:5361
Reference: URL:http://www.osvdb.org/5361
Reference: SECTRACK:1009788
Reference: URL:http://securitytracker.com/id?1009788
Reference: SECUNIA:11378
Reference: URL:http://secunia.com/advisories/11378
Reference: SECUNIA:11384
Reference: URL:http://secunia.com/advisories/11384
Reference: SECUNIA:11485
Reference: URL:http://secunia.com/advisories/11485
Reference: SECUNIA:11571
Reference: URL:http://secunia.com/advisories/11571
Reference: XF:ssmtp-die-logevent-format-string(15872)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15872
 

Votes:

 

Name: CVE-2004-0157

 

Description:
x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.

Status: Candidate
Phase: Assigned (20040213)
Reference: DEBIAN:DSA-484
Reference: URL:http://www.debian.org/security/2004/dsa-484
Reference: MISC:http://shellcode.org/Advisories/XONIX.txt
Reference: BID:10149
Reference: URL:http://www.securityfocus.com/bid/10149
Reference: OSVDB:5358
Reference: URL:http://www.osvdb.org/5358
Reference: SECTRACK:1009789
Reference: URL:http://securitytracker.com/id?1009789
Reference: SECUNIA:11382
Reference: URL:http://secunia.com/advisories/11382
Reference: XF:xonix-privilege-dropping(15873)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15873
 

Votes:

 

Name: CVE-2004-0158

 

Description:
Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040222 lbreakout2 < 2.4beta-2 local exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107755821705356&w=2
Reference: DEBIAN:DSA-445
Reference: URL:http://www.debian.org/security/2004/dsa-445
Reference: CONFIRM:http://security.debian.org/pool/updates/main/l/lbreakout2/lbreakout2_2.2.2-1woody1.diff.gz
Reference: BID:9712
Reference: URL:http://www.securityfocus.com/bid/9712
Reference: XF:breakout2-home-bo(15229)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15229
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0161

 

Description:
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.

Status: Candidate
Phase: Assigned (20040218)
Reference: BUGTRAQ:20040914 Corsaire Security Advisory - Multiple vendor MIME RFC2231 encoding issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109524928232568&w=2
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference: XF:mime-tools-parameter-encoding(9274)
Reference: URL:http://xforce.iss.net/xforce/xfdb/9274
 

Votes:

 

Name: CVE-2004-0162

 

Description:
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.

Status: Candidate
Phase: Assigned (20040218)
Reference: BUGTRAQ:20040914 Corsaire Security Advisory - Multiple vendor MIME RFC822 comment issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109517563513776&w=2
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/380375/mime.htm
Reference: XF:mime-rfc822-filtering-bypass(17332)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17332
 

Votes:

 

Name: CVE-2004-0163

 

Description:
Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.

Status: Candidate
Phase: Assigned (20040218)
Reference: BUGTRAQ:20040810 Corsaire Security Advisory - Sygate Secure Enterprise replay issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109215685731675&w=2
Reference: MISC:http://www.corsaire.com/advisories/c031120-002.txt
Reference: XF:sse-replay-dos(16945)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16945
 

Votes:

 

Name: CVE-2004-0164

 

Description:
KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.

Status: Candidate
Phase: Modified (20061101)
Reference: BUGTRAQ:20040113 unauthorized deletion of IPsec (and ISAKMP) SAs in racoon
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107403331309838&w=2
Reference: BUGTRAQ:20040114 Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107411758202662&w=2
Reference: APPLE:APPLE-SA-2004-02-23
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: NETBSD:NetBSD-SA2004-001
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-001.txt.asc
Reference: XF:openbsd-isakmp-initialcontact-delete-sa(14118)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14118
Reference: XF:openbsd-isakmp-invalidspi-delete-sa(14117)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14117
Reference: BID:9416
Reference: URL:http://www.securityfocus.com/bid/9416
Reference: BID:9417
Reference: URL:http://www.securityfocus.com/bid/9417
Reference: OVAL:oval:org.mitre.oval:def:947
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:947
 

Votes:

   ACCEPT(4) Baker, Cole, Armstrong, Cox
   NOOP(2) Christey, Wall
Voter Comments:
 
 CHANGE> [Cox changed vote from NOOP to ACCEPT]
 Christey> REDHAT:RHSA-2004:165
   URL:http://www.redhat.com/support/errata/RHSA-2004-165.html
 Christey> SCO:SCOSA-2005.10
   URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt


Name: CVE-2004-0166

 

Description:
Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."

Status: Candidate
Phase: Modified (20050510)
Reference: APPLE:APPLE-SA-2004-02-23
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: CERT-VN:VU#194238
Reference: URL:http://www.kb.cert.org/vuls/id/194238
Reference: SECUNIA:10959
Reference: URL:http://secunia.com/advisories/10959
Reference: XF:macosx-safari-unknown(14993)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14993
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0168

 

Description:
Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."

Status: Candidate
Phase: Modified (20050808)
Reference: APPLE:APPLE-SA-2004-02-23
Reference: URL:http://lists.apple.com/archives/security-announce/2004/Feb/msg00000.html
Reference: SECUNIA:10959
Reference: URL:http://secunia.com/advisories/10959/
Reference: XF:macos-corefoundation-unknown(15299)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15299
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0170

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040219)
 

Votes:

 

Name: CVE-2004-0172

 

Description:
Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.

Status: Candidate
Phase: Assigned (20040220)
Reference: FULLDISC:20031008 ltrace bug
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html
Reference: FULLDISC:20031008 ltrace bug
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html
Reference: BID:8790
Reference: URL:http://www.securityfocus.com/bid/8790
Reference: SECTRACK:1007896
Reference: URL:http://securitytracker.com/id?1007896
Reference: XF:ltrace-searchforcommand-bo(13389)
Reference: URL:http://xforce.iss.net/xforce/xfdb/13389
 

Votes:

 

Name: CVE-2004-0174

 

Description:
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."

Status: Candidate
Phase: Assigned (20040225)
Reference: BUGTRAQ:20040319 [ANNOUNCE] Apache HTTP Server 2.0.49 Released (fwd)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107973894328806&w=2
Reference: CONFIRM:http://www.apache.org/dist/httpd/CHANGES_1.3
Reference: SUNALERT:101555
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1
Reference: TRUSTIX:2004-0017
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108066914830552&w=2
Reference: APPLE:APPLE-SA-2004-05-03
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108369640424244&w=2
Reference: BUGTRAQ:20040512 [OpenPKG-SA-2004.021] OpenPKG Security Advisory (apache)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108437852004207&w=2
Reference: SLACKWARE:SSA:2004-133
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.529643
Reference: SUNALERT:57628
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1
Reference: TRUSTIX:2004-0027
Reference: URL:http://www.trustix.org/errata/2004/0027
Reference: GENTOO:GLSA-200405-22
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-22.xml
Reference: HP:SSRT4717
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108731648532365&w=2
Reference: MANDRAKE:MDKSA-2004:046
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:046
Reference: REDHAT:RHSA-2004:405
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-405.html
Reference: CERT-VN:VU#132110
Reference: URL:http://www.kb.cert.org/vuls/id/132110
Reference: OVAL:oval:org.mitre.oval:def:100110
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100110
Reference: SECUNIA:11170
Reference: URL:http://secunia.com/advisories/11170
Reference: BID:9921
Reference: URL:http://www.securityfocus.com/bid/9921
Reference: SECTRACK:1009495
Reference: URL:http://www.securitytracker.com/alerts/2004/Mar/1009495.html
Reference: OVAL:oval:org.mitre.oval:def:1982
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1982
Reference: XF:apache-socket-starvation-dos(15540)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15540
 

Votes:

 

Name: CVE-2004-0175

 

Description:
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.

Status: Candidate
Phase: Assigned (20040225)
Reference: CONFIRM:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=120147
Reference: CONFIRM:http://www.juniper.net/support/security/alerts/adv59739.txt
Reference: CONECTIVA:CLSA-2004:831
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000831
Reference: MANDRIVA:MDKSA-2005:100
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:100
Reference: MANDRIVA:MDVSA-2008:191
Reference: URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:191
Reference: REDHAT:RHSA-2005:106
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-106.html
Reference: REDHAT:RHSA-2005:074
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-074.html
Reference: REDHAT:RHSA-2005:165
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-165.html
Reference: REDHAT:RHSA-2005:481
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-481.html
Reference: REDHAT:RHSA-2005:495
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-495.html
Reference: REDHAT:RHSA-2005:562
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-562.html
Reference: REDHAT:RHSA-2005:567
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-567.html
Reference: SCO:SCOSA-2006.11
Reference: URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.11/SCOSA-2006.11.txt
Reference: SUSE:SuSE-SA:2004:009
Reference: URL:http://www.novell.com/linux/security/advisories/2004_09_kernel.html
Reference: CIAC:O-212
Reference: URL:http://www.ciac.org/ciac/bulletins/o-212.shtml
Reference: BID:9986
Reference: URL:http://www.securityfocus.com/bid/9986
Reference: OSVDB:9550
Reference: URL:http://www.osvdb.org/9550
Reference: SECUNIA:19243
Reference: URL:http://secunia.com/advisories/19243
Reference: SECUNIA:17135
Reference: URL:http://secunia.com/advisories/17135
Reference: XF:openssh-scp-file-overwrite(16323)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16323
 

Votes:

 

Name: CVE-2004-0176

 

Description:
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.

Status: Candidate
Phase: Assigned (20040225)
Reference: BUGTRAQ:20040323 Advisory 03/2004: Multiple (13) Ethereal remote overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108007072215742&w=2
Reference: MISC:http://security.e-matters.de/advisories/032004.html
Reference: CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00013.html
Reference: DEBIAN:DSA-511
Reference: URL:http://www.debian.org/security/2004/dsa-511
Reference: BUGTRAQ:20040329 LNSA-#2004-0007: Multiple security problems in Ethereal
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058005324316&w=2
Reference: GENTOO:GLSA-200403-07
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-07.xml
Reference: REDHAT:RHSA-2004:136
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-136.html
Reference: REDHAT:RHSA-2004:137
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-137.html
Reference: CONECTIVA:CLA-2004:835
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
Reference: MANDRAKE:MDKSA-2004:024
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
Reference: BUGTRAQ:20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213710306260&w=2
Reference: CERT-VN:VU#119876
Reference: URL:http://www.kb.cert.org/vuls/id/119876
Reference: CERT-VN:VU#125156
Reference: URL:http://www.kb.cert.org/vuls/id/125156
Reference: CERT-VN:VU#433596
Reference: URL:http://www.kb.cert.org/vuls/id/433596
Reference: CERT-VN:VU#591820
Reference: URL:http://www.kb.cert.org/vuls/id/591820
Reference: CERT-VN:VU#644886
Reference: URL:http://www.kb.cert.org/vuls/id/644886
Reference: CERT-VN:VU#659140
Reference: URL:http://www.kb.cert.org/vuls/id/659140
Reference: CERT-VN:VU#740188
Reference: URL:http://www.kb.cert.org/vuls/id/740188
Reference: CERT-VN:VU#864884
Reference: URL:http://www.kb.cert.org/vuls/id/864884
Reference: CERT-VN:VU#931588
Reference: URL:http://www.kb.cert.org/vuls/id/931588
Reference: OSVDB:6893
Reference: URL:http://www.osvdb.org/6893
Reference: OVAL:oval:org.mitre.oval:def:878
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:878
Reference: OVAL:oval:org.mitre.oval:def:887
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:887
Reference: SECUNIA:11185
Reference: URL:http://secunia.com/advisories/11185
Reference: XF:ethereal-multiple-dissectors-bo(15569)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15569
 

Votes:

 

Name: CVE-2004-0177

 

Description:
The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an information leak in which in-memory data is written to the device for the ext3 file system, which allows privileged users to obtain portions of kernel memory by reading the raw device.

Status: Candidate
Phase: Assigned (20040225)
Reference: CONECTIVA:CLA-2004:846
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-479
Reference: URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference: URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference: URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference: URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference: URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference: URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference: URL:http://www.debian.org/security/2004/dsa-495
Reference: ENGARDE:ESA-20040428-004
Reference: URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: FEDORA:FLSA:2336
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=2336
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:166
Reference: URL:http://rhn.redhat.com/errata/RHSA-2004-166.html
Reference: REDHAT:RHSA-2005:293
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-293.html
Reference: REDHAT:RHSA-2004:504
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-504.html
Reference: REDHAT:RHSA-2004:505
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-505.html
Reference: TRUSTIX:2004-0020
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference: MISC:http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ
Reference: CIAC:O-121
Reference: URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-126
Reference: URL:http://www.ciac.org/ciac/bulletins/o-126.shtml
Reference: CIAC:O-127
Reference: URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: BID:10152
Reference: URL:http://www.securityfocus.com/bid/10152
Reference: XF:linux-ext3-info-disclosure(15867)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15867
 

Votes:

 

Name: CVE-2004-0178

 

Description:
The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.

Status: Candidate
Phase: Assigned (20040225)
Reference: CONECTIVA:CLA-2004:846
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-479
Reference: URL:http://www.debian.org/security/2004/dsa-479
Reference: DEBIAN:DSA-480
Reference: URL:http://www.debian.org/security/2004/dsa-480
Reference: DEBIAN:DSA-481
Reference: URL:http://www.debian.org/security/2004/dsa-481
Reference: DEBIAN:DSA-482
Reference: URL:http://www.debian.org/security/2004/dsa-482
Reference: DEBIAN:DSA-489
Reference: URL:http://www.debian.org/security/2004/dsa-489
Reference: DEBIAN:DSA-491
Reference: URL:http://www.debian.org/security/2004/dsa-491
Reference: DEBIAN:DSA-495
Reference: URL:http://www.debian.org/security/2004/dsa-495
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2004:413
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-413.html
Reference: REDHAT:RHSA-2004:437
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-437.html
Reference: SGI:20040804-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc
Reference: MISC:http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA
Reference: CIAC:O-121
Reference: URL:http://www.ciac.org/ciac/bulletins/o-121.shtml
Reference: CIAC:O-127
Reference: URL:http://www.ciac.org/ciac/bulletins/o-127.shtml
Reference: CIAC:O-193
Reference: URL:http://www.ciac.org/ciac/bulletins/o-193.shtml
Reference: BID:9985
Reference: URL:http://www.securityfocus.com/bid/9985
Reference: XF:linux-sound-blaster-dos(15868)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15868
 

Votes:

 

Name: CVE-2004-0179

 

Description:
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

Status: Candidate
Phase: Assigned (20040225)
Reference: BUGTRAQ:20040416 void.at - neon format string bugs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108214147022626&w=2
Reference: DEBIAN:DSA-487
Reference: URL:http://www.debian.org/security/2004/dsa-487
Reference: FEDORA:FEDORA-2004-1552
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=1552
Reference: REDHAT:RHSA-2004:157
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-157.html
Reference: REDHAT:RHSA-2004:158
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-158.html
Reference: REDHAT:RHSA-2004:159
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-159.html
Reference: REDHAT:RHSA-2004:160
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-160.html
Reference: SGI:20040404-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
Reference: SUSE:SuSE-SA:2004:008
Reference: URL:http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html
Reference: SUSE:SuSE-SA:2004:009
Reference: URL:http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html
Reference: BUGTRAQ:20040416 [OpenPKG-SA-2004.016] OpenPKG Security Advisory (neon)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213873203477&w=2
Reference: GENTOO:GLSA-200405-01
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-01.xml
Reference: GENTOO:GLSA-200405-04
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-04.xml
Reference: MANDRAKE:MDKSA-2004:032
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:032
Reference: BID:10136
Reference: URL:http://www.securityfocus.com/bid/10136
Reference: OSVDB:5365
Reference: URL:http://www.osvdb.org/5365
Reference: OVAL:oval:org.mitre.oval:def:1065
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1065
Reference: SECUNIA:11363
Reference: URL:http://secunia.com/advisories/11363
 

Votes:

 

Name: CVE-2004-0180

 

Description:
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.

Status: Candidate
Phase: Assigned (20040225)
Reference: DEBIAN:DSA-486
Reference: URL:http://www.debian.org/security/2004/dsa-486
Reference: FEDORA:FEDORA-2004-1620
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108636445031613&w=2
Reference: FREEBSD:FreeBSD-SA-04:07
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc
Reference: GENTOO:GLSA-200404-13
Reference: URL:http://security.gentoo.org/glsa/glsa-200404-13.xml
Reference: MANDRAKE:MDKSA-2004:028
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:028
Reference: REDHAT:RHSA-2004:153
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-153.html
Reference: REDHAT:RHSA-2004:154
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-154.html
Reference: SGI:20040404-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
Reference: SLACKWARE:SSA:2004-108-02
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.400181
Reference: SUSE:SuSE-SA:2004:008
Reference: CONFIRM:ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/002_cvs.patch
Reference: OVAL:oval:org.mitre.oval:def:1042
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1042
Reference: SECUNIA:11368
Reference: URL:http://secunia.com/advisories/11368
Reference: SECUNIA:11371
Reference: URL:http://secunia.com/advisories/11371
Reference: SECUNIA:11374
Reference: URL:http://secunia.com/advisories/11374
Reference: SECUNIA:11375
Reference: URL:http://secunia.com/advisories/11375
Reference: SECUNIA:11377
Reference: URL:http://secunia.com/advisories/11377
Reference: SECUNIA:11380
Reference: URL:http://secunia.com/advisories/11380
Reference: SECUNIA:11391
Reference: URL:http://secunia.com/advisories/11391
Reference: SECUNIA:11400
Reference: URL:http://secunia.com/advisories/11400
Reference: SECUNIA:11405
Reference: URL:http://secunia.com/advisories/11405
Reference: SECUNIA:11548
Reference: URL:http://secunia.com/advisories/11548
Reference: XF:cvs-rcs-create-files(15864)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15864
 

Votes:

 

Name: CVE-2004-0181

 

Description:
The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.

Status: Candidate
Phase: Assigned (20040225)
Reference: ENGARDE:ESA-20040428-004
Reference: URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:029
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
Reference: REDHAT:RHSA-2005:663
Reference: URL:http://www.redhat.com/support/errata/RHSA-2005-663.html
Reference: REDHAT:RHSA-2004:504
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-504.html
Reference: TRUSTIX:2004-0020
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
Reference: TURBO:TLSA-2004-14
Reference: URL:http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
Reference: BID:10143
Reference: URL:http://www.securityfocus.com/bid/10143
Reference: FRSIRT:ADV-2005-1878
Reference: URL:http://www.frsirt.com/english/advisories/2005/1878
Reference: SECUNIA:17002
Reference: URL:http://secunia.com/advisories/17002
Reference: XF:linux-jfs-info-disclosure(15902)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15902
 

Votes:

 

Name: CVE-2004-0182

 

Description:
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

Status: Candidate
Phase: Assigned (20040225)
Reference: REDHAT:RHSA-2004:156
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-156.html
Reference: SGI:20040404-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
 

Votes:

 

Name: CVE-2004-0183

 

Description:
TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Status: Candidate
Phase: Assigned (20040302)
Reference: BUGTRAQ:20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108067265931525&w=2
Reference: MISC:http://www.rapid7.com/advisories/R7-0017.html
Reference: CONFIRM:http://www.tcpdump.org/tcpdump-changes.txt
Reference: DEBIAN:DSA-478
Reference: URL:http://www.debian.org/security/2004/dsa-478
Reference: FEDORA:FEDORA-2004-1468
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=1468
Reference: REDHAT:RHSA-2004:219
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-219.html
Reference: TRUSTIX:2004-0015
Reference: URL:http://www.trustix.org/errata/2004/0015
Reference: CERT-VN:VU#240790
Reference: URL:http://www.kb.cert.org/vuls/id/240790
Reference: BID:10003
Reference: URL:http://www.securityfocus.com/bid/10003
Reference: OVAL:oval:org.mitre.oval:def:972
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:972
Reference: SECTRACK:1009593
Reference: URL:http://securitytracker.com/id?1009593
Reference: SECUNIA:11258
Reference: URL:http://secunia.com/advisories/11258
Reference: SECUNIA:11320
Reference: URL:http://secunia.com/advisories/11320
Reference: XF:tcpdump-isakmp-delete-bo(15680)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15680
 

Votes:

 

Name: CVE-2004-0184

 

Description:
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Status: Candidate
Phase: Assigned (20040302)
Reference: BUGTRAQ:20040330 R7-0017: TCPDUMP ISAKMP payload handling denial-of-service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108067265931525&w=2
Reference: MISC:http://www.rapid7.com/advisories/R7-0017.html
Reference: CONFIRM:http://www.tcpdump.org/tcpdump-changes.txt
Reference: DEBIAN:DSA-478
Reference: URL:http://www.debian.org/security/2004/dsa-478
Reference: FEDORA:FEDORA-2004-1468
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=1468
Reference: REDHAT:RHSA-2004:219
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-219.html
Reference: TRUSTIX:2004-0015
Reference: URL:http://www.trustix.org/errata/2004/0015
Reference: CERT-VN:VU#492558
Reference: URL:http://www.kb.cert.org/vuls/id/492558
Reference: BID:10004
Reference: URL:http://www.securityfocus.com/bid/10004
Reference: OVAL:oval:org.mitre.oval:def:976
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:976
Reference: SECTRACK:1009593
Reference: URL:http://securitytracker.com/id?1009593
Reference: SECUNIA:11258
Reference: URL:http://secunia.com/advisories/11258
Reference: XF:tcpdump-isakmp-integer-underflow(15679)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15679
 

Votes:

 

Name: CVE-2004-0187

 

Description:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0185. Reason: This candidate is a reservation duplicate of CVE-2004-0185. Notes: All CVE users should reference CVE-2004-0185 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Status: Candidate
Phase: Assigned (20040302)
 

Votes:

 

Name: CVE-2004-0192

 

Description:
Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

Status: Candidate
Phase: Modified (20040813)
Reference: BUGTRAQ:20040227 Symantec Gateway Security Management Service Cross Site Scripting
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107790684732458&w=2
Reference: BID:9755
Reference: URL:http://www.securityfocus.com/bid/9755
Reference: XF:symantecgateway-error-xss(15330)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15330
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0195

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040309)
 

Votes:

 

Name: CVE-2004-0196

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040309)
 

Votes:

 

Name: CVE-2004-0197

 

Description:
Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-014
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-014.asp
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT-VN:VU#740716
Reference: URL:http://www.kb.cert.org/vuls/id/740716
Reference: BID:10112
Reference: URL:http://www.securityfocus.com/bid/10112
Reference: OVAL:oval:org.mitre.oval:def:968
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:968
Reference: XF:msjet-query-execute-code(15703)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15703
 

Votes:

 

Name: CVE-2004-0198

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040311)
 

Votes:

 

Name: CVE-2004-0199

 

Description:
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040512 MS04-015 - Windows Help Center - Dvdupgrade
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108437759930820&w=2
Reference: FULLDISC:20040512 MS04-015 - Windows Help Center - Dvdupgrade
Reference: URL:http://marc.theaimsgroup.com/?l=full-disclosure&m=108430407801825&w=2
Reference: MISC:http://www.exploitlabs.com/files/advisories/EXPL-A-2004-001-helpctr.txt
Reference: MS:MS04-015
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS04-015.mspx
Reference: CERT-VN:VU#484814
Reference: URL:http://www.kb.cert.org/vuls/id/484814
Reference: XF:win-hcp-code-execution(16095)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16095
Reference: BID:10321
Reference: URL:http://www.securityfocus.com/bid/10321
Reference: OVAL:oval:org.mitre.oval:def:1008
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1008
Reference: OVAL:oval:org.mitre.oval:def:1032
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1032
 

Votes:

 

Name: CVE-2004-0200

 

Description:
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040914 Microsoft GDIPlus.DLL JPEG Parsing Engine Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109524346729948&w=2
Reference: MS:MS04-028
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-028.asp
Reference: CERT:TA04-260A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-260A.html
Reference: CERT-VN:VU#297462
Reference: URL:http://www.kb.cert.org/vuls/id/297462
Reference: OVAL:oval:org.mitre.oval:def:1105
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1105
Reference: OVAL:oval:org.mitre.oval:def:1721
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1721
Reference: OVAL:oval:org.mitre.oval:def:2706
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2706
Reference: OVAL:oval:org.mitre.oval:def:3038
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3038
Reference: OVAL:oval:org.mitre.oval:def:3082
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3082
Reference: OVAL:oval:org.mitre.oval:def:3320
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3320
Reference: OVAL:oval:org.mitre.oval:def:3810
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3810
Reference: OVAL:oval:org.mitre.oval:def:3881
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3881
Reference: OVAL:oval:org.mitre.oval:def:4003
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4003
Reference: OVAL:oval:org.mitre.oval:def:4216
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4216
Reference: OVAL:oval:org.mitre.oval:def:4307
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4307
Reference: XF:win-jpeg-bo(16304)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16304
 

Votes:

 

Name: CVE-2004-0201

 

Description:
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

Status: Candidate
Phase: Assigned (20040311)
Reference: FULLDISC:20040714 HtmlHelp - .CHM File Heap Overflow
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023919.html
Reference: MS:MS04-023
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS04-023.mspx
Reference: CERT:TA04-196A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#920060
Reference: URL:http://www.kb.cert.org/vuls/id/920060
Reference: XF:win-htmlhelp-execute-code(16586)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16586
Reference: OVAL:oval:org.mitre.oval:def:1503
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1503
Reference: OVAL:oval:org.mitre.oval:def:1530
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1530
Reference: OVAL:oval:org.mitre.oval:def:2155
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2155
Reference: OVAL:oval:org.mitre.oval:def:3179
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3179
 

Votes:

 

Name: CVE-2004-0202

 

Description:
IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-016
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-016.asp
Reference: BID:10487
Reference: URL:http://www.securityfocus.com/bid/10487
Reference: OSVDB:6742
Reference: URL:http://www.osvdb.org/6742
Reference: OVAL:oval:org.mitre.oval:def:1027
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1027
Reference: OVAL:oval:org.mitre.oval:def:2190
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2190
Reference: OVAL:oval:org.mitre.oval:def:2413
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2413
Reference: OVAL:oval:org.mitre.oval:def:2516
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2516
Reference: OVAL:oval:org.mitre.oval:def:2705
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2705
Reference: SECUNIA:11802
Reference: URL:http://secunia.com/advisories/11802
Reference: XF:ms-directx-directplay-dos(16306)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16306
 

Votes:

 

Name: CVE-2004-0203

 

Description:
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-026
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-026.mspx
Reference: CERT-VN:VU#948750
Reference: URL:http://www.kb.cert.org/vuls/id/948750
Reference: OVAL:oval:org.mitre.oval:def:2016
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2016
Reference: XF:exchange-owa-execute-code(16583)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16583
 

Votes:

 

Name: CVE-2004-0204

 

Description:
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040502 Crystal Reports Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108360413811017&w=2
Reference: BUGTRAQ:20040608 Vulnerability: Arbitrary File Access & DoS in Crystal Reports
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108671836127360&w=2
Reference: CONFIRM:http://support.businessobjects.com/fix/hot/critical/bulletins/security_bulletin_june04.asp
Reference: MS:MS04-017
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-017.asp
Reference: BID:10260
Reference: URL:http://www.securityfocus.com/bid/10260
Reference: OSVDB:6748
Reference: URL:http://www.osvdb.org/6748
Reference: OVAL:oval:org.mitre.oval:def:1157
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1157
Reference: SECUNIA:11800
Reference: URL:http://secunia.com/advisories/11800
Reference: XF:crystalreports-file-deletion(16044)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16044
 

Votes:

 

Name: CVE-2004-0205

 

Description:
Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-021
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-021.asp
Reference: CERT:TA04-196A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#717748
Reference: URL:http://www.kb.cert.org/vuls/id/717748
Reference: CIAC:O-179
Reference: URL:http://www.ciac.org/ciac/bulletins/o-179.shtml
Reference: BID:10706
Reference: URL:http://www.securityfocus.com/bid/10706
Reference: OSVDB:7799
Reference: URL:http://www.osvdb.org/7799
Reference: OVAL:oval:org.mitre.oval:def:2204
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2204
Reference: SECUNIA:12061
Reference: URL:http://secunia.com/advisories/12061
Reference: XF:iis-redirect-bo(16578)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16578
 

Votes:

 

Name: CVE-2004-0206

 

Description:
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041013 Microsoft Windows NetDDE Service Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109786703930674&w=2
Reference: MS:MS04-031
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-031.asp
Reference: CERT-VN:VU#640488
Reference: URL:http://www.kb.cert.org/vuls/id/640488
Reference: BID:11372
Reference: URL:http://www.securityfocus.com/bid/11372
Reference: OVAL:oval:org.mitre.oval:def:1852
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1852
Reference: OVAL:oval:org.mitre.oval:def:2394
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2394
Reference: OVAL:oval:org.mitre.oval:def:3120
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3120
Reference: OVAL:oval:org.mitre.oval:def:3242
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3242
Reference: OVAL:oval:org.mitre.oval:def:4592
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4592
Reference: OVAL:oval:org.mitre.oval:def:5074
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5074
Reference: OVAL:oval:org.mitre.oval:def:6788
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6788
Reference: XF:win-netdde-bo(16556)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16556
Reference: XF:win-ms04031-patch(17657)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17657
Reference: SECUNIA:12803
Reference: URL:http://secunia.com/advisories/12803/
 

Votes:

 

Name: CVE-2004-0207

 

Description:
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041013 SetWindowLong Shatter Attacks
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109777417922695&w=2
Reference: MS:MS04-032
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference: XF:win-mngmt-api-gain-privileges(16579)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16579
Reference: XF:win-ms04032-patch(17658)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: CERT-VN:VU#218526
Reference: URL:http://www.kb.cert.org/vuls/id/218526
 

Votes:

 

Name: CVE-2004-0208

 

Description:
The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041013 EEYE: Windows VDM #UD Local Privilege Escalation
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109772135404427&w=2
Reference: MS:MS04-032
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference: OVAL:oval:org.mitre.oval:def:1751
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1751
Reference: OVAL:oval:org.mitre.oval:def:3161
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3161
Reference: OVAL:oval:org.mitre.oval:def:3953
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3953
Reference: OVAL:oval:org.mitre.oval:def:4316
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4316
Reference: OVAL:oval:org.mitre.oval:def:4762
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4762
Reference: XF:win-ms04032-patch(17658)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: XF:win-vdm-gain-privilege(16580)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16580
Reference: CERT-VN:VU#910998
Reference: URL:http://www.kb.cert.org/vuls/id/910998
 

Votes:

 

Name: CVE-2004-0209

 

Description:
Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-032
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference: BUGTRAQ:20041019 [EXPL] (MS04-032) Microsoft Windows XP Metafile (.emf) Heap Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109829067325779&w=2
Reference: BID:11375
Reference: URL:http://www.securityfocus.com/bid/11375
Reference: OVAL:oval:org.mitre.oval:def:1872
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1872
Reference: OVAL:oval:org.mitre.oval:def:2114
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2114
Reference: OVAL:oval:org.mitre.oval:def:2428
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2428
Reference: XF:win-emf-bo(16581)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16581
Reference: XF:win-ms04032-patch(17658)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: CERT-VN:VU#806278
Reference: URL:http://www.kb.cert.org/vuls/id/806278
 

Votes:

 

Name: CVE-2004-0210

 

Description:
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-020
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-020.asp
Reference: CERT:TA04-196A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#647436
Reference: URL:http://www.kb.cert.org/vuls/id/647436
Reference: XF:win-posix-bo(16590)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16590
Reference: OVAL:oval:org.mitre.oval:def:2166
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2166
Reference: OVAL:oval:org.mitre.oval:def:2847
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2847
 

Votes:

 

Name: CVE-2004-0211

 

Description:
The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-032
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-032.asp
Reference: OVAL:oval:org.mitre.oval:def:4893
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4893
Reference: XF:win2k3-kernel-cpu-dos(16582)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16582
Reference: XF:win-ms04032-patch(17658)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17658
Reference: CERT-VN:VU#119262
Reference: URL:http://www.kb.cert.org/vuls/id/119262
 

Votes:

 

Name: CVE-2004-0212

 

Description:
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040714 Microsoft Windows Task Scheduler '.job' Stack Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108981273009250&w=2
Reference: MISC:http://www.ngssoftware.com/advisories/mstaskjob.txt
Reference: BUGTRAQ:20040714 Unchecked buffer in mstask.dll
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108981403025596&w=2
Reference: MS:MS04-022
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-022.asp
Reference: CERT:TA04-196A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#228028
Reference: URL:http://www.kb.cert.org/vuls/id/228028
Reference: OVAL:oval:org.mitre.oval:def:1344
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1344
Reference: OVAL:oval:org.mitre.oval:def:1781
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1781
Reference: OVAL:oval:org.mitre.oval:def:1964
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1964
Reference: OVAL:oval:org.mitre.oval:def:3428
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3428
Reference: SECUNIA:12060
Reference: URL:http://secunia.com/advisories/12060
Reference: XF:win-taskscheduler-bo(16591)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16591
 

Votes:

 

Name: CVE-2004-0213

 

Description:
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040713 Microsoft Window Utility Manager Local Elevation of Privileges
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108975382413405&w=2
Reference: MS:MS04-019
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-019.asp
Reference: CERT:TA04-196A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#868580
Reference: URL:http://www.kb.cert.org/vuls/id/868580
Reference: XF:win-utilitymanager-gain-privileges(16592)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16592
Reference: OVAL:oval:org.mitre.oval:def:2495
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2495
 

Votes:

 

Name: CVE-2004-0214

 

Description:
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20040425 Microsoft's Explorer and Internet Explorer long share name buffer overflow.
Reference: URL:http://seclists.org/lists/bugtraq/2004/Apr/0322.html
Reference: FULLDISC:20040425 Microsoft's Explorer and Internet Explorer long share name buffer overflow.
Reference: URL:http://seclists.org/lists/fulldisclosure/2004/Apr/0933.html
Reference: MS:MS04-037
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx
Reference: MSKB:322857
Reference: URL:http://support.microsoft.com/default.aspx?scid=kb;en-us;322857
Reference: CERT-VN:VU#616200
Reference: URL:http://www.kb.cert.org/vuls/id/616200
Reference: MISC:http://www.securiteam.com/windowsntfocus/5JP0M1PCKI.html
Reference: BID:10213
Reference: URL:http://www.securityfocus.com/bid/10213
Reference: OSVDB:5687
Reference: URL:http://www.osvdb.org/5687
Reference: OVAL:oval:org.mitre.oval:def:1601
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1601
Reference: OVAL:oval:org.mitre.oval:def:1749
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1749
Reference: OVAL:oval:org.mitre.oval:def:2638
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2638
Reference: OVAL:oval:org.mitre.oval:def:4345
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4345
Reference: OVAL:oval:org.mitre.oval:def:5307
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5307
Reference: SECTRACK:1011647
Reference: URL:http://securitytracker.com/id?1011647
Reference: SECUNIA:11482
Reference: URL:http://secunia.com/advisories/11482/
Reference: XF:win-long-fileshare-bo(15956)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15956
Reference: XF:win-ms04037-patch(17662)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17662
 

Votes:

 

Name: CVE-2004-0215

 

Description:
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.

Status: Candidate
Phase: Assigned (20040311)
Reference: MS:MS04-018
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-018.asp
Reference: CERT:TA04-196A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
Reference: CERT-VN:VU#869640
Reference: URL:http://www.kb.cert.org/vuls/id/869640
Reference: XF:outlook-malformed-email-header-dos(16585)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16585
Reference: OVAL:oval:org.mitre.oval:def:1950
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1950
Reference: OVAL:oval:org.mitre.oval:def:2137
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2137
Reference: OVAL:oval:org.mitre.oval:def:2657
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2657
Reference: OVAL:oval:org.mitre.oval:def:3376
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3376
 

Votes:

 

Name: CVE-2004-0216

 

Description:
Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.

Status: Candidate
Phase: Assigned (20040311)
Reference: BUGTRAQ:20041012 Microsoft Internet Explorer Install Engine Control Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109760693512754&w=2
Reference: BUGTRAQ:20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110616383332055&w=2
Reference: NTBUGTRAQ:20050119 Microsoft Internet Explorer Install Engine Control Buffer Overflow (#NISR19012005a)
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=110619893620517&w=2
Reference: MISC:http://www.ngssoftware.com/advisories/msinsengfull.txt
Reference: MS:MS04-038
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms04-038.asp
Reference: CERT:TA04-293A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-293A.html
Reference: CERT-VN:VU#637760
Reference: URL:http://www.kb.cert.org/vuls/id/637760
Reference: OVAL:oval:org.mitre.oval:def:5316
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5316
Reference: OVAL:oval:org.mitre.oval:def:5329
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5329
Reference: OVAL:oval:org.mitre.oval:def:6100
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6100
Reference: OVAL:oval:org.mitre.oval:def:6600
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6600
Reference: OVAL:oval:org.mitre.oval:def:7717
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7717
Reference: OVAL:oval:org.mitre.oval:def:7865
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7865
Reference: XF:ie-installenginectl-setciffile-bo(17620)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17620
Reference: XF:ie-ms04038-patch(17651)
Reference: URL:http://xforce.iss.net/xforce/xfdb/17651
 

Votes:

 

Name: CVE-2004-0217

 

Description:
The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 Possible race condition in Symantec AntiVirus Scan Engine for Red
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107694800908164&w=2
Reference: XF:symantec-scanengine-race-condition(15215)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15215
Reference: BID:9662
Reference: URL:http://www.securityfocus.com/bid/9662
 

Votes:

   ACCEPT(2) Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Cox
   REVIEWING(1) Wall
Voter Comments:
 
 Frech> XF:symantec-scanengine-race-condition(15215)
   http://xforce.iss.net/xforce/xfdb/15215


Name: CVE-2004-0218

 

Description:
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference: MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX: March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#349113
Reference: URL:http://www.kb.cert.org/vuls/id/349113
Reference: BID:10028
Reference: URL:http://www.securityfocus.com/bid/10028
Reference: SECTRACK:1009468
Reference: URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: SECUNIA:11156
Reference: URL:http://secunia.com/advisories/11156
Reference: XF:openbsd-isakmp-zerolength-dos(15518)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15518
 

Votes:

 

Name: CVE-2004-0219

 

Description:
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference: MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX: March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#785945
Reference: URL:http://www.kb.cert.org/vuls/id/785945
Reference: BID:9907
Reference: URL:http://www.securityfocus.com/bid/9907
Reference: SECTRACK:1009468
Reference: URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: XF:openbsd-isakmp-ipsec-dos(15628)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15628
 

Votes:

 

Name: CVE-2004-0220

 

Description:
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via a an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference: MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX: March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#223273
Reference: URL:http://www.kb.cert.org/vuls/id/223273
Reference: BID:9907
Reference: URL:http://www.securityfocus.com/bid/9907
Reference: SECTRACK:1009468
Reference: URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: XF:openbsd-isakmp-integer-underflow(15629)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15629
 

Votes:

 

Name: CVE-2004-0221

 

Description:
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference: MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX: March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#524497
Reference: URL:http://www.kb.cert.org/vuls/id/524497
Reference: BID:9907
Reference: URL:http://www.securityfocus.com/bid/9907
Reference: SECTRACK:1009468
Reference: URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: XF:openbsd-isakmp-delete-dos(15630)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15630
 

Votes:

 

Name: CVE-2004-0222

 

Description:
Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.

Status: Candidate
Phase: Assigned (20040313)
Reference: BUGTRAQ:20040323 R7-0018: OpenBSD isakmpd payload handling denial-of-service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108008530028019&w=2
Reference: MISC:http://www.rapid7.com/advisories/R7-0018.html
Reference: OPENBSD:20040317 015: RELIABILITY FIX: March 17, 2004
Reference: URL:http://www.openbsd.org/errata.html
Reference: CERT-VN:VU#996177
Reference: URL:http://www.kb.cert.org/vuls/id/996177
Reference: BID:10028
Reference: URL:http://www.securityfocus.com/bid/10032
Reference: SECTRACK:1009468
Reference: URL:http://www.securitytracker.com/alerts/2004/Mar/1009468.html
Reference: XF:openbsd-isakmp-memory-leak(15519)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15519
 

Votes:

 

Name: CVE-2004-0223

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040315)
 

Votes:

 

Name: CVE-2004-0224

 

Description:
Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."

Status: Candidate
Phase: Modified (20050719)
Reference: CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=5767
Reference: SECUNIA:11087
Reference: URL:http://secunia.com/advisories/11087/
Reference: BID:9845
Reference: URL:http://www.securityfocus.com/bid/9845
Reference: XF:courier-codeset-converter-bo(15434)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15434
 

Votes:

   ACCEPT(4) Baker, Cole, Armstrong, Cox
   MODIFY(1) Frech
   NOOP(3) Green, Christey, Wall
Voter Comments:
 
 Frech> XF:courier-codeset-converter-bo(15434)
   http://xforce.iss.net/xforce/xfdb/15434
 Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2
 Christey> BUGTRAQ:20040329 [ GLSA 200403-06 ] Multiple remote buffer overflow vulnerabilities in Courier
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058112903373&w=2
 Christey> MISC:http://www.debian.org/security/nonvulns-woody#CVE-2004-0075
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]


Name: CVE-2004-0225

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040316)
 

Votes:

 

Name: CVE-2004-0226

 

Description:
Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

Status: Candidate
Phase: Assigned (20040317)
Reference: DEBIAN:DSA-497
Reference: URL:http://www.debian.org/security/2004/dsa-497
Reference: MANDRAKE:MDKSA-2004:039
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039
Reference: SUSE:SuSE-SA:2004:012
Reference: URL:http://www.novell.com/linux/security/advisories/2004_12_mc.html
Reference: REDHAT:RHSA-2004:172
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-172.html
Reference: GENTOO:GLSA-200405-21
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-21.xml
Reference: XF:midnight-commander-local-privileges(16016)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16016
 

Votes:

 

Name: CVE-2004-0227

 

Description:
Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.

Status: Candidate
Phase: Assigned (20040317)
Reference: CONFIRM:http://www.zoneminder.com/index.php?id=20&type=0&backPID=20&tt_news=29
Reference: XF:zoneminder-zms-bo(16136)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16136
Reference: BID:10340
Reference: URL:http://www.securityfocus.com/bid/10340
 

Votes:

 

Name: CVE-2004-0228

 

Description:
Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.

Status: Candidate
Phase: Assigned (20040317)
Reference: CONECTIVA:CLA-2004:852
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000852
Reference: FEDORA:FEDORA-2004-111
Reference: URL:http://fedoranews.org/updates/FEDORA-2004-111.shtml
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:050
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:050
Reference: SUSE:SuSE-SA:2004:010
Reference: URL:http://www.novell.com/linux/security/advisories/2004_10_kernel.html
Reference: SECUNIA:11429
Reference: URL:http://secunia.com/advisories/11429
Reference: SECUNIA:11464
Reference: URL:http://secunia.com/advisories/11464
Reference: SECUNIA:11486
Reference: URL:http://secunia.com/advisories/11486
Reference: SECUNIA:11491
Reference: URL:http://secunia.com/advisories/11491
Reference: SECUNIA:11683
Reference: URL:http://secunia.com/advisories/11683
Reference: XF:linux-cpufreq-info-disclosure(15951)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15951
 

Votes:

 

Name: CVE-2004-0229

 

Description:
The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.

Status: Candidate
Phase: Assigned (20040317)
Reference: CONECTIVA:CLA-2004:852
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000852
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:037
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:037
Reference: SUSE:SuSE-SA:2004:010
Reference: URL:http://www.novell.com/linux/security/advisories/2004_10_kernel.html
Reference: BID:10211
Reference: URL:http://www.securityfocus.com/bid/10211
Reference: XF:linux-framebuffer(15974)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15974
 

Votes:

 

Name: CVE-2004-0230

 

Description:
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

Status: Candidate
Phase: Assigned (20040317)
Reference: CISCO:20040420 TCP Vulnerabilities in Multiple IOS-Based Cisco Products
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040420-tcp-ios.shtml
Reference: CONFIRM:http://www.juniper.net/support/alert.html
Reference: HP:SSRT4696
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108506952116653&w=2
Reference: HP:HPSBST02161
Reference: URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded
Reference: HP:SSRT061264
Reference: URL:http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded
Reference: MS:MS05-019
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx
Reference: MS:MS06-064
Reference: URL:http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx
Reference: NETBSD:NetBSD-SA2004-006
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-006.txt.asc
Reference: SCO:SCOSA-2005.3
Reference: URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.3/SCOSA-2005.3.txt
Reference: SCO:SCOSA-2005.9
Reference: URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.9/SCOSA-2005.9.txt
Reference: SCO:SCOSA-2005.14
Reference: URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.14/SCOSA-2005.14.txt
Reference: SGI:20040403-01-A
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040403-01-A.asc
Reference: CERT:TA04-111A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-111A.html
Reference: CERT-VN:VU#415294
Reference: URL:http://www.kb.cert.org/vuls/id/415294
Reference: MISC:http://www.uniras.gov.uk/vuls/2004/236929/index.htm
Reference: BUGTRAQ:20040425 Perl code exploting TCP not checking RST ACK.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108302060014745&w=2
Reference: BID:10183
Reference: URL:http://www.securityfocus.com/bid/10183
Reference: FRSIRT:ADV-2006-3983
Reference: URL:http://www.frsirt.com/english/advisories/2006/3983
Reference: OSVDB:4030
Reference: URL:http://www.osvdb.org/4030
Reference: OVAL:oval:org.mitre.oval:def:4791
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4791
Reference: OVAL:oval:org.mitre.oval:def:2689
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2689
Reference: OVAL:oval:org.mitre.oval:def:3508
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3508
Reference: OVAL:oval:org.mitre.oval:def:270
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:270
Reference: SECUNIA:11440
Reference: URL:http://secunia.com/advisories/11440
Reference: SECUNIA:11458
Reference: URL:http://secunia.com/advisories/11458
Reference: SECUNIA:22341
Reference: URL:http://secunia.com/advisories/22341
Reference: XF:tcp-rst-dos(15886)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15886
 

Votes:

 

Name: CVE-2004-0231

 

Description:
Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

Status: Candidate
Phase: Assigned (20040317)
Reference: DEBIAN:DSA-497
Reference: URL:http://www.debian.org/security/2004/dsa-497
Reference: MANDRAKE:MDKSA-2004:039
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039
Reference: SUSE:SuSE-SA:2004:012
Reference: URL:http://www.novell.com/linux/security/advisories/2004_12_mc.html
Reference: REDHAT:RHSA-2004:172
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-172.html
Reference: GENTOO:GLSA-200405-21
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-21.xml
Reference: XF:midnight-commander-insecure-files(16020)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16020
 

Votes:

 

Name: CVE-2004-0232

 

Description:
Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

Status: Candidate
Phase: Assigned (20040317)
Reference: DEBIAN:DSA-497
Reference: URL:http://www.debian.org/security/2004/dsa-497
Reference: MANDRAKE:MDKSA-2004:039
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:039
Reference: SUSE:SuSE-SA:2004:012
Reference: URL:http://www.novell.com/linux/security/advisories/2004_12_mc.html
Reference: REDHAT:RHSA-2004:172
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-172.html
Reference: GENTOO:GLSA-200405-21
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-21.xml
Reference: XF:midnight-commander-format-string(16021)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16021
 

Votes:

 

Name: CVE-2004-0233

 

Description:
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

Status: Candidate
Phase: Assigned (20040317)
Reference: MANDRAKE:MDKSA-2004:031
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:031
Reference: REDHAT:RHSA-2004:174
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-174.html
Reference: REDHAT:RHSA-2004:175
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-175.html
Reference: SLACKWARE:SSA:2004-110
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404389
Reference: GENTOO:GLSA-200405-05
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-05.xml
Reference: BID:10178
Reference: URL:http://www.securityfocus.com/bid/10178
Reference: XF:utemper-symlink(15904)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15904
Reference: OVAL:oval:org.mitre.oval:def:979
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:979
 

Votes:

 

Name: CVE-2004-0234

 

Description:
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.

Status: Candidate
Phase: Assigned (20040317)
Reference: FULLDISC:20040501 LHa buffer overflows and directory traversal problems
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html
Reference: FULLDISC:20040502 Lha local stack overflow Proof Of Concept Code
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html
Reference: BUGTRAQ:20040510 [Ulf Harnhammar]: LHA Advisory + Patch
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108422737918885&w=2
Reference: BUGTRAQ:20060403 Barracuda LHA archiver security bug leads to remote compromise
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html
Reference: MISC:http://www.guay-leroux.com/projects/barracuda-advisory-LHA.txt
Reference: CONECTIVA:CLA-2004:840
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000840
Reference: DEBIAN:DSA-515
Reference: URL:http://www.debian.org/security/2004/dsa-515
Reference: FEDORA:FLSA:1833
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=1833
Reference: REDHAT:RHSA-2004:178
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-178.html
Reference: REDHAT:RHSA-2004:179
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-179.html
Reference: GENTOO:GLSA-200405-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-02.xml
Reference: FEDORA:FEDORA-2004-119
Reference: URL:http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html
Reference: BID:10243
Reference: URL:http://www.securityfocus.com/bid/10243
Reference: FRSIRT:ADV-2006-1220
Reference: URL:http://www.frsirt.com/english/advisories/2006/1220
Reference: OSVDB:5753
Reference: URL:http://www.osvdb.org/5753
Reference: OSVDB:5754
Reference: URL:http://www.osvdb.org/5754
Reference: OVAL:oval:org.mitre.oval:def:977
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:977
Reference: SECTRACK:1015866
Reference: URL:http://securitytracker.com/id?1015866
Reference: SECUNIA:19514
Reference: URL:http://secunia.com/advisories/19514
Reference: XF:lha-multiple-bo(16012)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16012
 

Votes:

 

Name: CVE-2004-0235

 

Description:
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

Status: Candidate
Phase: Assigned (20040317)
Reference: FULLDISC:20040501 LHa buffer overflows and directory traversal problems
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html
Reference: BUGTRAQ:20040510 [Ulf Harnhammar]: LHA Advisory + Patch
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108422737918885&w=2
Reference: CONECTIVA:CLA-2004:840
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000840
Reference: DEBIAN:DSA-515
Reference: URL:http://www.debian.org/security/2004/dsa-515
Reference: FEDORA:FLSA:1833
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=1833
Reference: REDHAT:RHSA-2004:178
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-178.html
Reference: REDHAT:RHSA-2004:179
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-179.html
Reference: GENTOO:GLSA-200405-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-02.xml
Reference: FEDORA:FEDORA-2004-119
Reference: URL:http://www.redhat.com/archives/fedora-announce-list/2004-May/msg00005.html
Reference: BID:10243
Reference: URL:http://www.securityfocus.com/bid/10243
Reference: XF:lha-directory-traversal(16013)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16013
Reference: OVAL:oval:org.mitre.oval:def:978
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:978
 

Votes:

 

Name: CVE-2004-0236

 

Description:
SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.

Status: Candidate
Phase: Modified (20050710)
Reference: BUGTRAQ:20040131 Advisory !
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107576894019530&w=2
Reference: BID:9884
Reference: URL:http://www.securityfocus.com/bid/9884
Reference: XF:thephototool-login-sql-injection(15007)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15007
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0237

 

Description:
Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.

Status: Candidate
Phase: Modified (20071031)
Reference: BUGTRAQ:20040131 Directory Traversal in Aprox PHP Portal.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577555527321&w=2
Reference: BID:9540
Reference: URL:http://www.securityfocus.com/bid/9540
Reference: OSVDB:10859
Reference: URL:http://www.osvdb.org/10859
Reference: SECTRACK:1008915
Reference: URL:http://securitytracker.com/id?1008915
Reference: XF:aproxphpportal-index-directory-traversal(15014)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15014
 

Votes:

   NOOP(5) Green, Wall, Cole, Armstrong, Cox

Name: CVE-2004-0238

 

Description:
Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040202 0verkill - little simple vulnerability.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107577335424509&w=2
Reference: FULLDISC:20040202 0verkill - little simple vulnerability.
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html
Reference: MISC:http://www.securiteam.com/securitynews/5AP010KC0C.html
Reference: BID:9550
Reference: URL:http://www.securityfocus.com/bid/9550
Reference: XF:overkill-client-multiple-bo(14999)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14999
Reference: XF:overkill-server-parsecommandline-bo(15000)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15000
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Wall, Cole, Cox

Name: CVE-2004-0239

 

Description:
SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040202 ZH2004-03SA (security advisory): Photopost PHP Pro 4.6 Sql
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582512023998&w=2
Reference: MISC:http://www.securiteam.com/securitynews/5KP010UC0W.html
Reference: XF:photopostphp-sql-injection(15008)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15008
Reference: BID:9557
Reference: URL:http://www.securityfocus.com/bid/9557
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0240

 

Description:
Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 X-Cart vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582648326448&w=2
Reference: XF:xcart-dotdot-directory-traversal(15033)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15033
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0241

 

Description:
X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 X-Cart vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582648326448&w=2
Reference: XF:xcart-perlbinary-execute-commands(15034)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15034
Reference: BID:9560
Reference: URL:http://www.securityfocus.com/bid/9560
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0242

 

Description:
X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 X-Cart vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107582648326448&w=2
Reference: XF:xcart-generalphp-obtain-information(15036)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15036
Reference: BID:9563
Reference: URL:http://www.securityfocus.com/bid/9563
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0243

 

Description:
AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.

Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040203 Re: sqwebmail web login
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107583269206044&w=2
Reference: BUGTRAQ:20040206 AIX password enumeration possible
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-02/0313.html
Reference: XF:aix-password-enumeration(15172)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15172
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0244

 

Description:
Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.

Status: Candidate
Phase: Modified (20050510)
Reference: CISCO:20040203 Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040203-cat6k.shtml
Reference: CERT-VN:VU#810062
Reference: URL:http://www.kb.cert.org/vuls/id/810062
Reference: SECUNIA:10780
Reference: URL:http://secunia.com/advisories/10780
Reference: BID:9562
Reference: URL:http://www.securityfocus.com/bid/9562
Reference: XF:cisco-malformed-frame-dos(15013)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15013
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   NOOP(2) Christey, Cox
Voter Comments:
 
 Christey> CERT-VN:VU#810062


Name: CVE-2004-0245

 

Description:
Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.

Status: Candidate
Phase: Modified (20050710)
Reference: BUGTRAQ:20040203 Web Crossing 4.x/5.x Denial of Service Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107586518120516&w=2
Reference: BID:9576
Reference: URL:http://www.securityfocus.com/bid/9576
Reference: XF:webcrossing-contentlength-post-dos(15022)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15022
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0246

 

Description:
Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.

Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040203 Les Commentaires (PHP) Include file
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107584083719763&w=2
Reference: BID:9536
Reference: URL:http://www.securityfocus.com/bid/9536
Reference: SECUNIA:10768
Reference: URL:http://secunia.com/advisories/10768/
Reference: XF:lescommentaires-multiple-file-include(15010)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15010
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0247

 

Description:
The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040203 Remote crash of Chaser game <= 1.50
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107584109420084&w=2
Reference: BID:9567
Reference: URL:http://www.securityfocus.com/bid/9567
Reference: XF:chaser-memory-dos(15031)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15031
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0248

 

Description:
Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.

Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040203 Multiple Vulnerabilities in PHPX
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107586932324901&w=2
Reference: BID:9569
Reference: URL:http://www.securityfocus.com/bid/9569
Reference: SECUNIA:10797
Reference: URL:http://secunia.com/advisories/10797/
Reference: XF:phpx-subject-html-injection(15050)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15050
Reference: XF:phpx-main-help-xss(15051)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15051
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0249

 

Description:
PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.

Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040203 Multiple Vulnerabilities in PHPX
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107586932324901&w=2
Reference: BUGTRAQ:20040316 PHPX 2.x - 3.2.4
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0154.html
Reference: BID:9569
Reference: URL:http://www.securityfocus.com/bid/9569
Reference: SECUNIA:10797
Reference: URL:http://secunia.com/advisories/10797/
Reference: XF:phpx-session-hijack(15512)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15512
Reference: XF:phpx-cookie-account-hijacking(15052)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15052
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0250

 

Description:
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040204 ZH2004-04SA (security advisory): Multiple Sql Injection
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107593114909696&w=2
Reference: MISC:http://www.zone-h.org/en/advisories/read/id=3864/
Reference: BID:9557
Reference: URL:http://www.securityfocus.com/bid/9557
Reference: XF:photopostphp-sql-injection(15008)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15008
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Wall, Cole, Cox

Name: CVE-2004-0251

 

Description:
Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040204 rxgoogle.cgi XSS Vulnerability.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107594183924958&w=2
Reference: XF:rxgoogle-query-xss(15043)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15043
Reference: BID:9575
Reference: URL:http://www.securityfocus.com/bid/9575
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0252

 

Description:
TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.

Status: Candidate
Phase: Modified (20050815)
Reference: BUGTRAQ:20040204 TYPSoft FTP Server 1.10 may be crashed
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107591511716707&w=2
Reference: BID:9573
Reference: URL:http://www.securityfocus.com/bid/9573
Reference: SECTRACK:1008943
Reference: URL:http://www.securitytracker.com/alerts/2004/Feb/1008943.html
Reference: XF:typsoft-empty-username-dos(15048)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15048
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Wall, Cole, Cox

Name: CVE-2004-0253

 

Description:
IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 IBM cloudscape SQL Database (DB2J) vulnerable to remote command
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107604065819233&w=2
Reference: BID:9583
Reference: URL:http://www.securityfocus.com/bid/9583
Reference: XF:cloudscape-sql-injection(15067)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15067
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0254

 

Description:
Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Possible Cross Site Scripting in Discuz! Board
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107606726417150&w=2
Reference: BID:9584
Reference: URL:http://www.securityfocus.com/bid/9584
Reference: XF:discuzboard-image-tag-xss(15066)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15066
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0255

 

Description:
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Remote crash Xlight ftp server 1.52
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107605633904122&w=2
Reference: XF:xlight-long-string-dos(15064)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15064
Reference: BID:9585
Reference: URL:http://www.securityfocus.com/bid/9585
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox
   REVIEWING(1) Christey
Voter Comments:
 
 Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40
   In the above URL, the vendor says that only one of 3 bugs
   reported in February 2004 were an "actual server bug," and the other 2
   "traced back into windows' dll and they won't happen if windows
   service pack is installed.
   
   The "actual server bug" is CVE-2004-0287.  The demonstration
   for *this* issue shows that the application breaks in comctl32.dll.
   So, this candidate may be erroneous, and an interesting side effect of
   another bug that's not related to xlight at all.
   
   Thus, this candidate may need to be REJECTED.


Name: CVE-2004-0258

 

Description:
Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.

Status: Candidate
Phase: Proposed (20040318)
Reference: VULNWATCH:20040204 [VulnWatch] Multiple File Format Vulnerabilities (Overruns) in REALOne & RealPlayer
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0027.html
Reference: BUGTRAQ:20040204 Multiple File Format Vulnerabilities (Overruns) in REALOne & RealPlayer
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107608748813559&w=2
Reference: MISC:http://www.nextgenss.com/advisories/realone.txt
Reference: CONFIRM:http://www.service.real.com/help/faq/security/040123_player/EN/
Reference: CERT-VN:VU#473814
Reference: URL:http://www.kb.cert.org/vuls/id/473814
Reference: CIAC:O-075
Reference: URL:http://www.ciac.org/ciac/bulletins/o-075.shtml
Reference: BID:9579
Reference: URL:http://www.securityfocus.com/bid/9579
Reference: XF:realoneplayer-multiple-file-bo(15040)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15040
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   NOOP(1) Cox

Name: CVE-2004-0259

 

Description:
The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040206 formmail (PHP) Upload file using CSS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107619109629629&w=2
Reference: XF:jack-formmail-file-upload(15079)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15079
Reference: BID:9591
Reference: URL:http://www.securityfocus.com/bid/9591
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0260

 

Description:
The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107619501815888&w=2
Reference: FULLDISC:20040206 CactuSoft CactuShop 5.0 Lite shopping cart software backdoor
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016819.html
Reference: XF:cactushoplite-backdoor(15063)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15063
Reference: BID:9589
Reference: URL:http://www.securityfocus.com/bid/9589
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0262

 

Description:
Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.

Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040207 The Palace 3.x (Client) Stack Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634556632195&w=2
Reference: VULNWATCH:20040207 The Palace 3.x (Client) Stack Overflow Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0033.html
Reference: MISC:http://www.elitehaven.net/thepalace.txt
Reference: XF:palace-server-address-bo(15074)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15074
Reference: BID:9602
Reference: URL:http://www.securityfocus.com/bid/9602
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0264

 

Description:
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040208 PalmOS httpd accept() queue overflow DoS vulnerability.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634638201570&w=2
Reference: XF:palmhttpd-accept-bo(15090)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15090
Reference: BID:9608
Reference: URL:http://www.securityfocus.com/bid/9608
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0265

 

Description:
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040208 [waraxe-2004-SA#002] - Cross-Site Scripting (XSS) in Php-Nuke 7.1.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107634727520936&w=2
Reference: XF:phpnuke-mulitple-xss(15076)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15076
Reference: BID:9605
Reference: URL:http://www.securityfocus.com/bid/9605
Reference: BID:9613
Reference: URL:http://www.securityfocus.com/bid/9613
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0266

 

Description:
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers obtain the administrator password via the c_mid parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040208 [waraxe-2004-SA#003] - SQL injection in Php-Nuke 7.1.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635110327066&w=2
Reference: XF:phpnuke-publicmessage-sql-injection(15080)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15080
Reference: BID:9615
Reference: URL:http://www.securityfocus.com/bid/9615
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0267

 

Description:
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.

Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040209 [local problems] eTrust Virus Protection 6.0 InoculateIT for linux
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635584431518&w=2
Reference: MISC:http://www.excluded.org/advisories/advisory10.txt
Reference: BID:9616
Reference: URL:http://www.securityfocus.com/bid/9616
Reference: OSVDB:4735
Reference: URL:http://www.osvdb.org/4735
Reference: OSVDB:4855
Reference: URL:http://www.osvdb.org/4855
Reference: OSVDB:4856
Reference: URL:http://www.osvdb.org/4856
Reference: SECUNIA:10833
Reference: URL:http://secunia.com/advisories/10833
Reference: XF:etrust-inoculateit-symlink(15102)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15102
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0268

 

Description:
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643394724891&w=2
Reference: FULLDISC:20040210 XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016988.html
Reference: XF:evolutionx-command-line-dos(15104)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15104
Reference: BID:9631
Reference: URL:http://www.securityfocus.com/bid/9631
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0269

 

Description:
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 [SCAN Associates Sdn Bhd Security Advisory] PHPNuke 6.9 > and below SQL Injection in multiple module
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643348117646&w=2
Reference: MISC:http://www.scan-associates.net/papers/phpnuke69.txt
Reference: XF:phpnuke-modules-sql-injection(15115)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15115
Reference: BID:9630
Reference: URL:http://www.securityfocus.com/bid/9630
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0271

 

Description:
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.

Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040210 XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643014606515&w=2
Reference: BID:9625
Reference: URL:http://www.securityfocus.com/bid/9625
Reference: XF:maxwebportal-multiple-xss(15120)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15120
Reference: XF:maxwebportal-register-xss(15122)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15122
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0272

 

Description:
SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643014606515&w=2
Reference: XF:maxwebportal-personalmesssages-sql-injection(15121)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15121
Reference: BID:9625
Reference: URL:http://www.securityfocus.com/bid/9625
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0275

 

Description:
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040211 ZH2004-05SA (security advisory): Sql Injection Vulnerability in BosDates
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107651618613575&w=2
Reference: MISC:http://www.zone-h.org/en/advisories/read/id=3925/
Reference: XF:bosdates-calendar-sql-injection(15133)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15133
Reference: BID:9639
Reference: URL:http://www.securityfocus.com/bid/9639
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0277

 

Description:
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.

Status: Candidate
Phase: Proposed (20040318)
Reference: FULLDISC:20040207 DreamFTP Server 1.02 Buffer Overflow
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016871.html
Reference: MISC:http://www.security-protocols.com/modules.php?name=News&file=article&sid=1722
Reference: BUGTRAQ:20040211 Re: [Full-Disclosure] DreamFTP Server 1.02 Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107656166402882&w=2
Reference: XF:dreamftp-username-format-string(15070)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15070
Reference: BID:9600
Reference: URL:http://www.securityfocus.com/bid/9600
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0278

 

Description:
Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040211 Denial of Service in Ratbag's game engine
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107655269820530&w=2
Reference: XF:ratbag-data-length-dos(15188)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15188
Reference: BID:9644
Reference: URL:http://www.securityfocus.com/bid/9644
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0279

 

Description:
AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040212 aimSniff.pl file "deletion" (local)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107662243303439&w=2
Reference: XF:aim-sniff-symlink(15199)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15199
Reference: BID:9653
Reference: URL:http://www.securityfocus.com/bid/9653
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0280

 

Description:
Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Apache Http Server Reveals Script Source Code to Remote Users And Any Users Can Access Resin Forbidden Directory ("/WEB-INF/")
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635084830547&w=2
Reference: BID:9614
Reference: URL:http://www.securityfocus.com/bid/9614
Reference: XF:resin-source-disclosure(15085)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15085
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Wall, Armstrong, Cox

Name: CVE-2004-0281

 

Description:
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040205 Apache Http Server Reveals Script Source Code to Remote Users And Any Users Can Access Resin Forbidden Directory ("/WEB-INF/")
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107635084830547&w=2
Reference: BID:9617
Reference: URL:http://www.securityfocus.com/bid/9617
Reference: XF:resin-dotdot-directory-traversal(15087)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15087
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0282

 

Description:
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.

Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040212 crob ftpd Denial of Service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107665920909374&w=2
Reference: BID:9651
Reference: URL:http://www.securityfocus.com/bid/9651
Reference: OSVDB:6621
Reference: URL:http://www.osvdb.org/6621
Reference: SECUNIA:10882
Reference: URL:http://secunia.com/advisories/10882
Reference: XF:crob-multiple-connections-dos(15201)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15201
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0283

 

Description:
Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040212 Symlink vulnerabilities in mailmgr
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107665013714517&w=2
Reference: XF:mailmgr-insecure-temp-directory (15203)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15203
Reference: BID:9654
Reference: URL:http://www.securityfocus.com/bid/9654
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0284

 

Description:
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040210 ASPR #2004-01-20-1: Internet Explorer/Outlook double null character DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107643134712133&w=2
Reference: XF:ie-host-null-dos(15127)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15127
Reference: BID:9629
Reference: URL:http://www.securityfocus.com/bid/9629
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Christey, Armstrong, Cox
   REVIEWING(1) Wall
Voter Comments:
 
 Christey> MISC:http://www.acrossecurity.com/aspr/ASPR-2004-01-20-1-PUB.txt


Name: CVE-2004-0285

 

Description:
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.

Status: Candidate
Phase: Modified (20070123)
Reference: BUGTRAQ:20040214 AllMyVisitors PHP Code Injection vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696235424865&w=2
Reference: BUGTRAQ:20040214 AllMyGuests PHP Code Injection vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696209514155&w=2
Reference: BUGTRAQ:20040214 AllMyLinks PHP Code Injection vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696291728750&w=2
Reference: BID:9664
Reference: URL:http://www.securityfocus.com/bid/9664
Reference: OSVDB:6721
Reference: URL:http://www.osvdb.org/6721
Reference: XF:allmyvisitors-file-include(15228)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15228
Reference: XF:allmyguests-php-file-include(15227)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15227
Reference: XF:allmylinks-file-include(15226)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15226
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0286

 

Description:
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040215 buffer overflow in Robot FTP Server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696194306878&w=2
Reference: XF:robot-username-bo(15225)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15225
Reference: BID:9672
Reference: URL:http://www.securityfocus.com/bid/9672
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0287

 

Description:
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.

Status: Candidate
Phase: Modified (20050518)
Reference: BUGTRAQ:20040215 Xlight ftp server 1.52 RETR bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695172917263&w=2
Reference: XF:xlight-retr-dos(15220)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15220
Reference: BID:9668
Reference: URL:http://www.securityfocus.com/bid/9668
 

Votes:

   NOOP(5) Christey, Wall, Cole, Armstrong, Cox
Voter Comments:
 
 Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32
   and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says
   that this was fixed in 1.55.
   
   Also, DELREF BID:9627 - it's not a clean match.
   Instead, ADDREF BID:9668


Name: CVE-2004-0288

 

Description:
Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040215 Buffer overflow in mnoGoSearch
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695139930726&w=2
Reference: XF:mnogosearch-udmdoctotextbuf-bo(15209)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15209
Reference: BID:9667
Reference: URL:http://www.securityfocus.com/bid/9667
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0289

 

Description:
Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040215 problems with database files in 'SignatureDB'
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695113832648&w=2
Reference: BID:9661
Reference: URL:http://www.securityfocus.com/bid/9661
Reference: XF:signaturedb-sdbscan-bo(15217)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15217
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0290

 

Description:
Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 Broadcast client buffer-overflow in Purge Jihad <= 2.0.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107695064204362&w=2
Reference: CONFIRM:http://purge.worthplaying.com/phpbb/viewtopic.php?t=1167
Reference: BID:9671
Reference: URL:http://www.securityfocus.com/bid/9671
Reference: XF:purge-battletype-map-bo(15216)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15216
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0291

 

Description:
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 Another YabbSE SQL Injection
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107696318522985&w=2
Reference: BID:9674
Reference: URL:http://www.securityfocus.com/bid/9674
Reference: XF:yabb-post-sql-injection(15224)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15224
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(2) Wall, Cox

Name: CVE-2004-0292

 

Description:
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 KarjaSoft Sami HTTP Server 1.0.4 Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703630913205&w=2
Reference: MISC:http://www.security-protocols.com/modules.php?name=News&file=article&sid=1746
Reference: BID:9679
Reference: URL:http://www.securityfocus.com/bid/9679
Reference: XF:sami-http-get-bo(15237)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15237
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0293

 

Description:
Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 ZH2004-06SA (security advisory): ShopCartCGI v2.3 Remote
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703602707450&w=2
Reference: MISC:http://www.zone-h.org/en/advisories/read/id=3962/
Reference: XF:shopcartcgi-dotdot-directory-traversal(14982)
Reference: URL:http://xforce.iss.net/xforce/xfdb/14982
Reference: BID:9670
Reference: URL:http://www.securityfocus.com/bid/9670
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0294

 

Description:
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 YABB information leakage on failed login
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703591314745&w=2
Reference: BID:9677
Reference: URL:http://www.securityfocus.com/bid/9677
Reference: XF:yabb-invalidmessage-obtain-information(15236)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15236
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0295

 

Description:
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 Broker FTP DoS (Message Server)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107705346817241&w=2
Reference: MISC:http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html
Reference: XF:broker-ftp-tsftpsrv-dos(15242)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15242
Reference: BID:9680
Reference: URL:http://www.securityfocus.com/bid/9680
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0296

 

Description:
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.

Status: Candidate
Phase: Modified (20050707)
Reference: BUGTRAQ:20040217 Broker FTP DoS (Message Server)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107705346817241&w=2
Reference: MISC:http://www.securiteam.com/windowsntfocus/5IP0B0AC1I.html
Reference: XF:broker-ftp-dos(15241)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15241
Reference: BID:9680
Reference: URL:http://www.securityfocus.com/bid/9680
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox
   REVIEWING(1) Christey
Voter Comments:
 
 Christey> The description is incomplete.  Wonder what it was about the
   original researcher that was important enough to note?
 Christey> What was I saying in the desc about the original researcher???


Name: CVE-2004-0298

 

Description:
CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 CesarFTP 0.99 : 100% employment of computer resources
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712057628250&w=2
Reference: BID:9666
Reference: URL:http://www.securityfocus.com/bid/9666
Reference: XF:cesarftp-userpass-dos(15252)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15252
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0299

 

Description:
Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 Smallftpd 1.0.3 DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107714207708375&w=2
Reference: BID:9684
Reference: URL:http://www.securityfocus.com/bid/9684
Reference: XF:smallftpd-forwardslash-dos(15262)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15262
 

Votes:

   NOOP(4) Wall, Cole, Armstrong, Cox

Name: CVE-2004-0300

 

Description:
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

Status: Candidate
Phase: Modified (20051204)
Reference: BUGTRAQ:20040218 ZH2004-07SA (security advisory): Multiple Sql injection
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712117913185&w=2
Reference: MISC:http://www.zone-h.org/en/advisories/read/id=3972/
Reference: MISC:http://www.systemsecure.org/advisories/ssadvisory16022004.php
Reference: OSVDB:3973
Reference: URL:http://www.osvdb.org/3973
Reference: SECTRACK:1009092
Reference: URL:http://securitytracker.com/alerts/2004/Feb/1009092.html
Reference: SECUNIA:10902
Reference: URL:http://secunia.com/advisories/10902/
Reference: XF:onlinestorekit-more-sql-injection(15232)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15232
Reference: BID:9676
Reference: URL:http://www.securityfocus.com/bid/9676
Reference: BID:9687
Reference: URL:http://www.securityfocus.com/bid/9687
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0301

 

Description:
Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.

Status: Candidate
Phase: Modified (20051204)
Reference: MISC:http://www.systemsecure.org/advisories/ssadvisory16022004.php
Reference: BID:9676
Reference: URL:http://www.securityfocus.com/bid/9676
Reference: SECTRACK:1009079
Reference: URL:http://securitytracker.com/alerts/2004/Feb/1009079.html
Reference: SECUNIA:10902
Reference: URL:http://secunia.com/advisories/10902/
Reference: XF:onlinestorekit-more-xss(15235)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15235
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0302

 

Description:
Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712123305706&w=2
Reference: MISC:http://www.zone-h.org/en/advisories/read/id=3973/
Reference: XF:owls-file-retrieval(15249)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15249
Reference: BID:9689
Reference: URL:http://www.securityfocus.com/bid/9689
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0303

 

Description:
OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 ZH2004-08SA (security advisory): OWLS 1.0 Remote arbitrary files
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712123305706&w=2
Reference: MISC:http://www.zone-h.org/en/advisories/read/id=3973/
Reference: XF:owls-file-retrieval(15249)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15249
Reference: BID:9689
Reference: URL:http://www.securityfocus.com/bid/9689
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0304

 

Description:
SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 WebCortex Webstores2000 version 6.0 multiple security vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712159425226&w=2
Reference: MISC:http://www.s-quadra.com/advisories/Adv-20040218.txt
Reference: XF:webstores-browseitems-sql-injection(15253)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15253
Reference: BID:7766
Reference: URL:http://www.securityfocus.com/bid/7766
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0305

 

Description:
Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040218 WebCortex Webstores2000 version 6.0 multiple security vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712159425226&w=2
Reference: XF:webstores-error-xss(15254)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15254
Reference: BID:9693
Reference: URL:http://www.securityfocus.com/bid/9693
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0308

 

Description:
Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connection to the VxWorks shell.

Status: Candidate
Phase: Modified (20040820)
Reference: CISCO:20040219 Cisco ONS 15327, ONS 15454, ONS 15454 SDH, and ONS 15600 Vulnerabilities
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040219-ONS.shtml
Reference: XF:cisco-ons-gain-access(15266)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15266
Reference: BID:9699
Reference: URL:http://www.securityfocus.com/bid/9699
Reference: OSVDB:4010
Reference: URL:http://www.osvdb.org/4010
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   NOOP(1) Cox

Name: CVE-2004-0310

 

Description:
Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040219 LiveJournal XSS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107722627800820&w=2
Reference: BID:9700
Reference: URL:http://www.securityfocus.com/bid/9700
Reference: XF:livejournal-url-xss(15268)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15268
 

Votes:

   NOOP(5) Cox, Christey, Wall, Cole, Armstrong
Voter Comments:
 
 Christey> Despite the description, the specific affected versions are
   not actually known.  Either they need to be removed or we need
   some source that can confirm the affected versions.


Name: CVE-2004-0311

 

Description:
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040216 APC 9606 SmartSlot Web/SNMP management card "backdoor"
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107703696631367&w=2
Reference: BUGTRAQ:20040219 Re: Fw: APC 9606 SmartSlot Web/SNMP management card "backdoor"
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107721020803565&w=2
Reference: CONFIRM:http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=3131&p_created=1077139129
Reference: XF:apc-smartslot-default-password(15238)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15238
Reference: BID:9681
Reference: URL:http://www.securityfocus.com/bid/9681
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Cox, Wall

Name: CVE-2004-0312

 

Description:
Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040217 SNMP community string disclosure in Linksys WAP55AG
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107712101324233&w=2
Reference: BUGTRAQ:20040219 Re: SNMP community string disclosure in Linksys WAP55AG
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107730681012131&w=2
Reference: XF:linksys-snmp-strings-disclosure(15257)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15257
Reference: BID:9688
Reference: URL:http://www.securityfocus.com/bid/9688
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0313

 

Description:
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040220 Remote Buffer Overflow in PSOProxy 0.91
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107730731900261&w=2
Reference: BID:9706
Reference: URL:http://www.securityfocus.com/bid/9706
Reference: XF:psoproxy-long-get-bo(15275)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15275
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0314

 

Description:
Cross-site scripting (XSS) vulnerability in done.jsp in WebzEdit 1.9 and earlier allows remote attackers to execute arbitrary script as other users via the message parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040221 Cross Site Scripting in WebzEdit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107757029514146&w=2
Reference: XF:webzedit-done-xss(15289)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15289
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0315

 

Description:
Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Remote Buffer Overflow in Avirt Voice 4.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756584609841&w=2
Reference: XF:avirt-voice-get-bo(15288)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15288
Reference: BID:9721
Reference: URL:http://www.securityfocus.com/bid/9721
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0316

 

Description:
Buffer overflow in Avirt Soho 4.3 allows remote attackers to cause a denial of service (crash) via (1) a large GET request to port 1080 or (2) a large GET request of % characters to port 8080.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20030223 Multiple Remote Buffer Overflow in Avirt Soho 4.3
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756666701194&w=2
Reference: XF:avirt-soho-multiple-bo(15286)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15286
Reference: BID:9722
Reference: URL:http://www.securityfocus.com/bid/9722
Reference: BID:9723
Reference: URL:http://www.securityfocus.com/bid/9723
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0317

 

Description:
Buffer overflow in eauth in Load Sharing Facility 4.x, 5.x, and 6.x allows local users or remote attackers within the LSF cluster to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long LSF_From_PC parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Lam3rZ Security Advisory #1/2004: LSF eauth vulnerability leads to remote code execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756611501236&w=2
Reference: XF:lsf-eauth-execute-code(15282)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15282
Reference: BID:9719
Reference: URL:http://www.securityfocus.com/bid/9719
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0318

 

Description:
Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Lam3rZ Security Advisory #2/2004: LSF eauth vulnerability leads to a possibility of controlling cluster jobs on behalf of other users
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756600403557&w=2
Reference: XF:lsf-eauth-process-hijack(15278)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15278
Reference: BID:9724
Reference: URL:http://www.securityfocus.com/bid/9724
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0319

 

Description:
Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 ezBoard Cross Site Scripting Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756639427140&w=2
Reference: XF:ezboard-font-xss(15287)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15287
Reference: BID:9725
Reference: URL:http://www.securityfocus.com/bid/9725
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(3) Cox, Balinsky, Wall

Name: CVE-2004-0321

 

Description:
Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Remote server crash in Team Factor <= 1.25
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756001412888&w=2
Reference: MISC:http://www.zone-h.org/advisories/read/id=4006
Reference: BID:9708
Reference: URL:http://www.securityfocus.com/bid/9708
Reference: XF:teamfactor-packet-dos(15274)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15274
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0322

 

Description:
Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.

Status: Candidate
Phase: Modified (20050718)
Reference: BUGTRAQ:20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756526625179&w=2
Reference: BUGTRAQ:20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html
Reference: CONFIRM:http://www.xmbforum.com/community/boards/viewthread.php?tid=746859
Reference: BID:9726
Reference: URL:http://www.securityfocus.com/bid/9726
Reference: XF:xmb-multiple-scripts-xss(15292)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15292
Reference: XF:xmb-bbcode-execute-code(15294)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15294
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0323

 

Description:
Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.

Status: Candidate
Phase: Modified (20051128)
Reference: BUGTRAQ:20040223 [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107756526625179&w=2
Reference: BUGTRAQ:20040225 Re: [waraxe-2004-SA#004] - Multiple vulnerabilities in XMB 1.8 Partagium Final SP2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html
Reference: BUGTRAQ:20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html
Reference: CONFIRM:http://www.xmbforum.com/community/boards/viewthread.php?tid=746859
Reference: BID:9726
Reference: URL:http://www.securityfocus.com/bid/9726
Reference: XF:xmb-multiple-sql-injection(15295)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15295
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0324

 

Description:
Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 Lam3rZ Security Advisory #3/2004: A bug in Confirm leads to remote command execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107757320401858&w=2
Reference: XF:confirm-header-gain-access(15290)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15290
Reference: BID:9728
Reference: URL:http://www.securityfocus.com/bid/9728
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0325

 

Description:
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty".

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 TYPSoft FTP Server 1.10 multiple vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107764173821905&w=2
Reference: BID:9702
Reference: URL:http://www.securityfocus.com/bid/9702
Reference: XF:typsoft-ftp-command-dos(15306)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15306
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0326

 

Description:
Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040222 GateKeeper Pro 4.7 buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107755692400728&w=2
Reference: FULLDISC:20040222 GateKeeper Pro 4.7 buffer overflow
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017703.html
Reference: BID:9716
Reference: URL:http://www.securityfocus.com/bid/9716
Reference: XF:gatekeeper-long-get-bo(15277)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15277
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(3) Cox, Balinsky, Wall

Name: CVE-2004-0327

 

Description:
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040223 ZH2004-09SA (security advisory): PhpNewsManager Remote arbitrary
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107772470111000&w=2
Reference: MISC:http://www.zone-h.org/advisories/read/id=4024
Reference: XF:phpnewsmanager-dotdot-directory-traversal(15283)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15283
Reference: BID:9720
Reference: URL:http://www.securityfocus.com/bid/9720
 

Votes:

   ACCEPT(1) Cole
   NOOP(4) Cox, Balinsky, Wall, Armstrong

Name: CVE-2004-0328

 

Description:
Gigabyte Gn-B46B 2.4Ghz wireless broadband router firmware 1.003.00 allows local users on the same local network as the router to bypass authentication by using a copy of the router's html menu on a separate system.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040224 Gigabyte Broadband Router - Multiple Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107766719227942&w=2
Reference: BID:9740
Reference: URL:http://www.securityfocus.com/bid/9740
Reference: XF:gigabyte-gnb46b-bypass-authentication(15313)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15313
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0329

 

Description:
FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 Denial Of Service in FreeChat 1.1.1a
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107781043621074&w=2
Reference: XF:freechat-string-dos(15321)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15321
Reference: BID:9744
Reference: URL:http://www.securityfocus.com/bid/9744
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0330

 

Description:
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 [vulnwatch] Serv-U MDTM Command Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107781164214399&w=2
Reference: MISC:http://www.cnhonker.com/advisory/serv-u.mdtm.txt
Reference: XF:servu-mdtm-bo(15323)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15323
Reference: BID:9751
Reference: URL:http://www.securityfocus.com/bid/9751
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0331

 

Description:
Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 Dell OpenManage Web Server Heap Overflow (Pre-Auth)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107781539829143&w=2
Reference: MISC:http://sh0dan.org/files/domadv.txt
Reference: XF:dell-openmanage-ocsgetoeminpathfile-bo(15325)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15325
Reference: BID:9750
Reference: URL:http://www.securityfocus.com/bid/9750
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Cox, Wall, Armstrong

Name: CVE-2004-0332

 

Description:
Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040226 Extremail Security Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107783767517850&w=2
Reference: XF:extremail-password-gain-access(15329)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15329
Reference: BID:9754
Reference: URL:http://www.securityfocus.com/bid/9754
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0333

 

Description:
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.

Status: Candidate
Phase: Modified (20050808)
Reference: IDEFENSE:20040227 WinZip MIME Parsing Buffer Overflow Vulnerability
Reference: URL:http://www.idefense.com/application/poi/display?id=76&type=vulnerabiliti&flashstatus=true
Reference: CONFIRM:http://www.winzip.com/fmwz90.htm
Reference: CONFIRM:http://www.openpkg.org/security/OpenPKG-SA-2004.006-uudeview.html
Reference: CERT-VN:VU#116182
Reference: URL:http://www.kb.cert.org/vuls/id/116182
Reference: CIAC:O-092
Reference: URL:http://www.ciac.org/ciac/bulletins/o-092.shtml
Reference: BID:9758
Reference: URL:http://www.securityfocus.com/bid/9758
Reference: OSVDB:4119
Reference: URL:http://www.osvdb.org/4119
Reference: SECUNIA:10995
Reference: URL:http://secunia.com/advisories/10995
Reference: SECUNIA:11019
Reference: URL:http://secunia.com/advisories/11019
Reference: XF:uudeview-multiple-bo(15490)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15490
Reference: XF:winzip-mime-bo(15336)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15336
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   NOOP(2) Cox, Christey
Voter Comments:
 
 Christey> Consider this Gentoo reference:
   BUGTRAQ:20040328 [ GLSA 200403-05 ] UUDeview MIME Buffer Overflow
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108057738810928&w=2
   
   May need to rephrase this description to emphasize UUDeview
   over WinZip.


Name: CVE-2004-0334

 

Description:
InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.

Status: Candidate
Phase: Modified (20060816)
Reference: BUGTRAQ:20040227 InnoMedia VideoPhone Authorization Bypass
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799556111784&w=2
Reference: OSVDB:4809
Reference: URL:http://www.osvdb.org/4809
Reference: SECTRACK:1009522
Reference: URL:http://securitytracker.com/alerts/2004/Mar/1009522.html
Reference: XF:InnoMedia-videophone-bypass-authentication(15636)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15636
 

Votes:

   NOOP(5) Cox, Christey, Wall, Cole, Armstrong
Voter Comments:
 
 Christey> According to SecurityTracker.com, the initial advisory
   erroneously mentions Axis 1200:
   MISC:http://securitytracker.com/alerts/2004/Mar/1009522.html


Name: CVE-2004-0335

 

Description:
LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799540630302&w=2
Reference: BUGTRAQ:20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html
Reference: XF:602pro-directory-listing(15349)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15349
Reference: BID:9780
Reference: URL:http://www.securityfocus.com/bid/9780
 

Votes:

   ACCEPT(1) Cole
   NOOP(2) Cox, Wall
   REJECT(1) Armstrong
Voter Comments:
 
 Armstrong> If this is a design feature - then it should not be classed as a vulnerability.


Name: CVE-2004-0337

 

Description:
Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 LAN SUITE Web Mail 602Pro Multiple Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799540630302&w=2
Reference: BUGTRAQ:20040310 Re: LAN SUITE Web Mail 602Pro Multiple Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0096.html
Reference: XF:602pro-index-xss(15351)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15351
Reference: BID:9777
Reference: URL:http://www.securityfocus.com/bid/9777
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Cox, Wall, Armstrong

Name: CVE-2004-0338

 

Description:
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 Invision Power Board SQL injection!
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799527428834&w=2
Reference: XF:invision-search-sql-injection(15343)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15343
Reference: BID:9766
Reference: URL:http://www.securityfocus.com/bid/9766
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0339

 

Description:
Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040228 New phpBB ViewTopic.php Cross Site Scripting Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107799508130700&w=2
Reference: XF:phpbb-viewtopicphp-xss(15348)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15348
Reference: BID:9765
Reference: URL:http://www.securityfocus.com/bid/9765
 

Votes:

   ACCEPT(1) Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0340

 

Description:
Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.

Status: Candidate
Phase: Modified (20050719)
Reference: BUGTRAQ:20040228 Critical WFTPD buffer overflow vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107801208004699&w=2
Reference: BID:9767
Reference: URL:http://www.securityfocus.com/bid/9767
Reference: SECUNIA:11001
Reference: URL:http://secunia.com/advisories/11001
Reference: XF:wftpd-ftp-commands-bo(15340)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15340
 

Votes:

   ACCEPT(2) Wall, Armstrong
   NOOP(2) Cox, Cole

Name: CVE-2004-0341

 

Description:
WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.

Status: Candidate
Phase: Modified (20050719)
Reference: BUGTRAQ:20040228 Multiple WFTPD Denial of Service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107801142924976&w=2
Reference: BID:9767
Reference: URL:http://www.securityfocus.com/bid/9767
Reference: OSVDB:4115
Reference: URL:http://www.osvdb.org/4115
Reference: SECUNIA:11001
Reference: URL:http://secunia.com/advisories/11001
Reference: XF:wftpd-string-0Ahbyte-dos(15341)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15341
 

Votes:

   ACCEPT(2) Wall, Armstrong
   NOOP(2) Cox, Cole

Name: CVE-2004-0342

 

Description:
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.

Status: Candidate
Phase: Modified (20050718)
Reference: BUGTRAQ:20040228 Multiple WFTPD Denial of Service vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107801142924976&w=2
Reference: BID:9767
Reference: URL:http://www.securityfocus.com/bid/9767
Reference: OSVDB:4116
Reference: URL:http://www.osvdb.org/4116
Reference: SECUNIA:11001
Reference: URL:http://secunia.com/advisories/11001
Reference: XF:wftpd-ftp-command-dos(15342)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15342
 

Votes:

   ACCEPT(2) Wall, Armstrong
   NOOP(2) Cox, Cole

Name: CVE-2004-0343

 

Description:
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040301 YabbSE (3 on 1)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107816202813083&w=2
Reference: XF:yabb-multiple-sql-injection(15354)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15354
Reference: BID:9774
Reference: URL:http://www.securityfocus.com/bid/9774
 

Votes:

   ACCEPT(3) Stracener, Cole, Armstrong
   NOOP(3) Cox, Balinsky, Wall
   REVIEWING(1) Green

Name: CVE-2004-0344

 

Description:
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040301 YabbSE (3 on 1)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107816202813083&w=2
Reference: BID:9774
Reference: URL:http://www.securityfocus.com/bid/9774
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0345

 

Description:
Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040301 Clients broadcast buffer overflow in Red Faction <= 1.20
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107816217901923&w=2
Reference: XF:redfaction-bo(15353)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15353
Reference: BID:9775
Reference: URL:http://www.securityfocus.com/bid/9775
 

Votes:

   ACCEPT(1) Stracener
   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0346

 

Description:
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040302 The Cult of a Cardinal Number
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107824679817240&w=2
Reference: XF:proftpd-offbyone-bo(15387)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15387
Reference: BID:9782
Reference: URL:http://www.securityfocus.com/bid/9782
 

Votes:

   ACCEPT(2) Stracener, Armstrong
   NOOP(3) Cox, Wall, Cole

Name: CVE-2004-0348

 

Description:
SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 Spider Sales shopping cart software multiple security vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833097705486&w=2
Reference: MISC:http://www.s-quadra.com/advisories/Adv-20040303.txt
Reference: XF:spidersales-userid-sql-injection(15371)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15371
Reference: BID:9799
Reference: URL:http://www.securityfocus.com/bid/9799
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Cox, Wall, Armstrong

Name: CVE-2004-0349

 

Description:
Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 directory traversal in GWeb 0.6
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833161617397&w=2
Reference: XF:gweb-dotdot-directory-traversal(15381)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15381
Reference: BID:9742
Reference: URL:http://www.securityfocus.com/bid/9742
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0350

 

Description:
SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 Spider Sales shopping cart software multiple security vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833097705486&w=2
Reference: FULLDISC:20040303 Spider Sales shopping cart software multiple security vulnerabilities
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html
Reference: MISC:http://www.s-quadra.com/advisories/Adv-20040303.txt
Reference: XF:spidersales-weak-encryption(15370)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15370
Reference: BID:9799
Reference: URL:http://www.securityfocus.com/bid/9799
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Cox, Wall, Armstrong

Name: CVE-2004-0351

 

Description:
Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040303 Spider Sales shopping cart software multiple security vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107833097705486&w=2
Reference: FULLDISC:20040303 Spider Sales shopping cart software multiple security vulnerabilities
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-March/018177.html
Reference: XF:spidersales-weak-encryption(15370)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15370
Reference: BID:9799
Reference: URL:http://www.securityfocus.com/bid/9799
 

Votes:

   ACCEPT(1) Cole
   NOOP(3) Cox, Wall, Armstrong

Name: CVE-2004-0352

 

Description:
Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.

Status: Candidate
Phase: Proposed (20040318)
Reference: CISCO:20040304 Cisco CSS 11000 Series Content Services Switches Malformed UDP Packet Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040304-css.shtml
Reference: CERT-VN:VU#363374
Reference: URL:http://www.kb.cert.org/vuls/id/363374
Reference: XF:cisco-css-udp-dos(15388)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15388
Reference: BID:9806
Reference: URL:http://www.securityfocus.com/bid/9806
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   NOOP(2) Cox, Christey
Voter Comments:
 
 Christey> According to the Details section of the advisory, the
   vulnerability can only be exploited through the management port, which
   is "available solely through the physical management interface."  So,
   change the description to point out that physical access is required.
   Thanks to esCERT-UPC for pointing this out.


Name: CVE-2004-0353

 

Description:
Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040304 GNU Anubis buffer overflows and format string bugs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107843915424588&w=2
Reference: MLIST:[bug-anubis] 20040228 Important security update
Reference: URL:http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html
Reference: BUGTRAQ:20040310 GNU Anubis 3.6.2 remote root exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107894315012081&w=2
Reference: BID:9772
Reference: URL:http://www.securityfocus.com/bid/9772
Reference: XF:anubis-ident-bo(15345)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15345
 

Votes:

   ACCEPT(4) Green, Baker, Cole, Armstrong
   NOOP(2) Cox, Wall
Voter Comments:
 
 Green> VERIFIED-BY-SOMEONE-I-TRUST


Name: CVE-2004-0354

 

Description:
Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040304 GNU Anubis buffer overflows and format string bugs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107843915424588&w=2
Reference: MLIST:[bug-anubis] 20040228 Important security update
Reference: URL:http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html
Reference: BID:9772
Reference: URL:http://www.securityfocus.com/bid/9772
Reference: XF:anubis-format-string(15346)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15346
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Cox, Wall

Name: CVE-2004-0355

 

Description:
Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040305 Invision Power Board 1.3 Final Path Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107850510428567&w=2
Reference: XF:invision-invalid-path-disclosure(15400)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15400
Reference: BID:9810
Reference: URL:http://www.securityfocus.com/bid/9810
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0357

 

Description:
Stack-based buffer overflows in SL Mail Pro 2.0.9 allow remote attackers to execute arbitrary code via (1) user.dll, (2) loadpageadmin.dll or (3) loadpageuser.dll.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040305 SLWebMail Multiple Buffer Overflow Vulnerabilities (#NISR05022004b)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107850432827699&w=2
Reference: CONFIRM:http://216.26.170.92/Download/webfiles/Patches/SLMPPatch-2.0.14.pdf
Reference: MISC:http://www.nextgenss.com/advisories/slmailwm.txt
Reference: XF:slmail-slwebmail-bo(15399)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15399
Reference: BID:9808
Reference: URL:http://www.securityfocus.com/bid/9808
 

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   NOOP(2) Cox, Wall

Name: CVE-2004-0358

 

Description:
Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040305 VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107851556116088&w=2
Reference: BUGTRAQ:20040307 RE: VirtuaNews Admin Panel 1.0.3 Pro Cross Site Scripting Vulnerabillity
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2004-03/0069.html
Reference: XF:virtuanews-multiple-xss(15402)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15402
Reference: BID:9812
Reference: URL:http://www.securityfocus.com/bid/9812
Reference: BID:9819
Reference: URL:http://www.securityfocus.com/bid/9819
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0359

 

Description:
Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.

Status: Candidate
Phase: Modified (20050719)
Reference: BUGTRAQ:20040305 Invision Power Board v1.3 Final Cross Site Scripting Vulnerabillity
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107851589701916&w=2
Reference: BID:9768
Reference: URL:http://www.securityfocus.com/bid/9768
Reference: OSVDB:4154
Reference: URL:http://www.osvdb.org/4154
Reference: SECUNIA:11053
Reference: URL:http://secunia.com/advisories/11053
Reference: XF:invision-xss(15403)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15403
 

Votes:

   NOOP(4) Cox, Wall, Cole, Armstrong

Name: CVE-2004-0360

 

Description:
Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:200470305 O-088: Sun passwd(1) Command Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107852274423414&w=2
Reference: SUNALERT:57454
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57454
Reference: CERT-VN:VU#694782
Reference: URL:http://www.kb.cert.org/vuls/id/694782
Reference: CIAC:O-088
Reference: URL:http://www.ciac.org/ciac/bulletins/o-088.shtml
Reference: XF:solaris-passwd-gain-privileges(15327)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15327
Reference: BID:9757
Reference: URL:http://www.securityfocus.com/bid/9757
 

Votes:

   ACCEPT(4) Wall, Baker, Cole, Armstrong
   NOOP(1) Cox

Name: CVE-2004-0361

 

Description:
The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.

Status: Candidate
Phase: Proposed (20040318)
Reference: BUGTRAQ:20040306 Safari javascript array overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107861828510106&w=2
Reference: MISC:http://www.insecure.ws/article.php?story=2004021918172533
Reference: BID:9815
Reference: URL:http://www.securityfocus.com/bid/9815
Reference: XF:safari-array-dos(15413)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15413
 

Votes:

   ACCEPT(2) Cole, Armstrong
   NOOP(2) Cox, Wall

Name: CVE-2004-0362

 

Description:
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

Status: Candidate
Phase: Assigned (20040318)
Reference: BUGTRAQ:20040318 EEYE: Internet Security Systems PAM ICQ Server Response Processing Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107965651712378&w=2
Reference: EEYE:AD20040318
Reference: URL:http://www.eeye.com/html/Research/Advisories/AD20040318.html
Reference: ISS:20040318 Vulnerability in ICQ Parsing in ISS Products
Reference: URL:http://xforce.iss.net/xforce/alerts/id/166
Reference: CERT-VN:VU#947254
Reference: URL:http://www.kb.cert.org/vuls/id/947254
Reference: CIAC:O-104
Reference: URL:http://www.ciac.org/ciac/bulletins/o-104.shtml
Reference: BID:9913
Reference: URL:http://www.securityfocus.com/bid/9913
Reference: OSVDB:4355
Reference: URL:http://www.osvdb.org/4355
Reference: SECUNIA:11073
Reference: URL:http://secunia.com/advisories/11073
Reference: XF:pam-icq-parsing-bo(15442)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15442
Reference: XF:witty-worm-propagation(15543)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15543
 

Votes:

 

Name: CVE-2004-0363

 

Description:
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.

Status: Candidate
Phase: Assigned (20040319)
Reference: BUGTRAQ:20040319 Norton AntiSpam Remote Buffer Overrun (#NISR19042004a)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107970870606638&w=2
Reference: MISC:http://www.nextgenss.com/advisories/antispam.txt
Reference: BUGTRAQ:20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107980262324362&w=2
Reference: CONFIRM:http://www.sarc.com/avcenter/security/Content/2004.03.19.html
Reference: CERT-VN:VU#344718
Reference: URL:http://www.kb.cert.org/vuls/id/344718
Reference: BID:9916
Reference: URL:http://www.securityfocus.com/bid/9916
Reference: SECUNIA:11169
Reference: URL:http://secunia.com/advisories/11169
Reference: XF:nas-launchcustomrulewizard-bo(15536)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15536
 

Votes:

 

Name: CVE-2004-0364

 

Description:
The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.

Status: Candidate
Phase: Assigned (20040319)
Reference: BUGTRAQ:20040319 Norton Internet Security Remote Command Execution (#NISR19042004b)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107970885922442&w=2
Reference: MISC:http://www.nextgenss.com/advisories/nisrce.txt
Reference: BUGTRAQ:20040319 Ref: NGSSoftware Advisories NISR19042004a and NISR19042004b
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107980262324362&w=2
Reference: CONFIRM:http://www.sarc.com/avcenter/security/Content/2004.03.19.html
Reference: CERT-VN:VU#549054
Reference: URL:http://www.kb.cert.org/vuls/id/549054
Reference: BID:9915
Reference: URL:http://www.securityfocus.com/bid/9915
Reference: SECUNIA:11168
Reference: URL:http://secunia.com/advisories/11168
Reference: XF:norton-is-launchurl-command-execution(15538)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15538
 

Votes:

 

Name: CVE-2004-0365

 

Description:
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.

Status: Candidate
Phase: Assigned (20040322)
Reference: MLIST:[ethereal-dev] 20040318 ethereal radius dissector vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ethereal-dev&m=107962966700423&w=2
Reference: CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00013.html
Reference: BUGTRAQ:20040329 LNSA-#2004-0007: Multiple security problems in Ethereal
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058005324316&w=2
Reference: GENTOO:GLSA-200403-07
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-07.xml
Reference: CONECTIVA:CLA-2004:835
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
Reference: MANDRAKE:MDKSA-2004:024
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
Reference: REDHAT:RHSA-2004:136
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-136.html
Reference: REDHAT:RHSA-2004:137
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-137.html
Reference: BUGTRAQ:20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213710306260&w=2
Reference: CERT-VN:VU#124454
Reference: URL:http://www.kb.cert.org/vuls/id/124454
Reference: OVAL:oval:org.mitre.oval:def:879
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:879
Reference: OVAL:oval:org.mitre.oval:def:891
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:891
Reference: SECUNIA:11185
Reference: URL:http://secunia.com/advisories/11185
Reference: XF:ethereal-radius-dos(15571)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15571
 

Votes:

 

Name: CVE-2004-0366

 

Description:
SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

Status: Candidate
Phase: Assigned (20040322)
Reference: DEBIAN:DSA-469
Reference: URL:http://www.debian.org/security/2004/dsa-469
Reference: BID:10266
Reference: URL:http://www.securityfocus.com/bid/10266
Reference: SECUNIA:11237
Reference: URL:http://secunia.com/advisories/11237
Reference: XF:pam-pgsql-sql-injection(15651)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15651
 

Votes:

 

Name: CVE-2004-0367

 

Description:
Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.

Status: Candidate
Phase: Assigned (20040322)
Reference: CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00013.html
Reference: MLIST:[Ethereal-dev] 20040416 Possibly incorrect CVE entry CAN-2004-0367
Reference: URL:http://www.ethereal.com/lists/ethereal-dev/200404/msg00296.html
Reference: BUGTRAQ:20040329 LNSA-#2004-0007: Multiple security problems in Ethereal
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108058005324316&w=2
Reference: GENTOO:GLSA-200403-07
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-07.xml
Reference: CONECTIVA:CLA-2004:835
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
Reference: MANDRAKE:MDKSA-2004:024
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
Reference: REDHAT:RHSA-2004:136
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-136.html
Reference: REDHAT:RHSA-2004:137
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-137.html
Reference: CERT-VN:VU#792286
Reference: URL:http://www.kb.cert.org/vuls/id/792286
Reference: OVAL:oval:org.mitre.oval:def:880
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:880
Reference: OVAL:oval:org.mitre.oval:def:905
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:905
Reference: SECUNIA:11185
Reference: URL:http://secunia.com/advisories/11185
Reference: XF:ethereal-zero-presentation-dos(15570)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15570
 

Votes:

 

Name: CVE-2004-0368

 

Description:
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

Status: Candidate
Phase: Assigned (20040323)
Reference: VULNWATCH:20040323 how much fun can you have with UDP?
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0064.html
Reference: MLIST:[Dailydave] 20040323 dtlogin advisory
Reference: URL:http://lists.immunitysec.com/pipermail/dailydave/2004-March/000402.html
Reference: MISC:http://www.immunitysec.com/downloads/dtlogin.sxw.pdf
Reference: HP:HPSBUX01038
Reference: URL:http://www.auscert.org.au/render.html?it=4103&cid=3734
Reference: SGI:20040801-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040801-01-P
Reference: SUNALERT:57539
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57539-1&searchclause=security
Reference: SUNALERT:101478
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101478-1
Reference: CERT-VN:VU#179804
Reference: URL:http://www.kb.cert.org/vuls/id/179804
Reference: CIAC:O-129
Reference: URL:http://www.ciac.org/ciac/bulletins/o-129.shtml
Reference: OVAL:oval:org.mitre.oval:def:1436
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1436
Reference: SECUNIA:11210
Reference: URL:http://secunia.com/advisories/11210/
Reference: SECUNIA:11214
Reference: URL:http://secunia.com/advisories/11214/
Reference: SECUNIA:11614
Reference: URL:http://secunia.com/advisories/11614/
Reference: SECUNIA:11495
Reference: URL:http://secunia.com/advisories/11495/
Reference: BID:9958
Reference: URL:http://www.securityfocus.com/bid/9958
Reference: XF:cde-dtlogin-double-free(15581)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15581
 

Votes:

 

Name: CVE-2004-0369

 

Description:
Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.

Status: Candidate
Phase: Assigned (20040324)
Reference: ISS:20040826 Entrust LibKmp Library Buffer Overflow
Reference: URL:http://xforce.iss.net/xforce/alerts/id/181
Reference: CONFIRM:http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html
Reference: AUSCERT:ESB-2004.0538
Reference: URL:http://www.auscert.org.au/render.html?it=4339
Reference: CIAC:O-206
Reference: URL:http://www.ciac.org/ciac/bulletins/o-206.shtml
Reference: BID:11039
Reference: URL:http://www.securityfocus.com/bid/11039
Reference: XF:isakmp-spi-size-bo(15669)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15669
 

Votes:

 

Name: CVE-2004-0370

 

Description:
The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.

Status: Candidate
Phase: Assigned (20040324)
Reference: FREEBSD:FreeBSD-SA-04:06
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:06.ipv6.asc
Reference: BID:9992
Reference: URL:http://www.securityfocus.com/bid/9992
Reference: SECUNIA:11233
Reference: URL:http://secunia.com/advisories/11233
Reference: XF:freebsd-ipv6-dos(15662)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15662
 

Votes:

 

Name: CVE-2004-0371

 

Description:
Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.

Status: Candidate
Phase: Assigned (20040324)
Reference: CONFIRM:http://www.pdc.kth.se/heimdal/advisory/2004-04-01/
Reference: DEBIAN:DSA-476
Reference: URL:http://www.debian.org/security/2004/dsa-476
Reference: FREEBSD:FreeBSD-SA-04:08
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:08.heimdal.asc
Reference: OPENBSD:20040530 009: SECURITY FIX: May 30, 2004
Reference: URL:ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/009_kerberos.patch
Reference: GENTOO:GLSA-200404-09
Reference: URL:http://security.gentoo.org/glsa/glsa-200404-09.xml
Reference: XF:heimdal-cross-realm-spoofing(15701)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15701
 

Votes:

 

Name: CVE-2004-0372

 

Description:
xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.

Status: Candidate
Phase: Assigned (20040325)
Reference: BUGTRAQ:20040320 xine-check/xine-bugreport symlink vulnerability.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107997911025558&w=2
Reference: DEBIAN:DSA-477
Reference: URL:http://www.debian.org/security/2004/dsa-477
Reference: GENTOO:GLSA-200404-20
Reference: URL:http://security.gentoo.org/glsa/glsa-200404-20.xml
Reference: BID:9939
Reference: URL:http://www.securityfocus.com/bid/9939
Reference: XF:xine-xinebugreport-xinecheck-symlink(15564)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15564
 

Votes:

 

Name: CVE-2004-0373

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040326)
 

Votes:

 

Name: CVE-2004-0374

 

Description:
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.

Status: Candidate
Phase: Assigned (20040329)
Reference: MLIST:[interchange-announce] 20040329 Security Problem in Interchange
Reference: URL:http://www.icdevgroup.org/pipermail/interchange-announce/2004/000043.html
Reference: CONFIRM:http://ftp.icdevgroup.org/interchange/5.0/WHATSNEW
Reference: DEBIAN:DSA-471
Reference: URL:http://www.debian.org/security/2004/dsa-471
Reference: BID:10005
Reference: URL:http://www.securityfocus.com/bid/10005
Reference: SECUNIA:11234
Reference: URL:http://secunia.com/advisories/11234
Reference: XF:interchange-url-obtain-information(15670)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15670
 

Votes:

 

Name: CVE-2004-0375

 

Description:
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.

Status: Candidate
Phase: Assigned (20040329)
Reference: BUGTRAQ:20040423 EEYE: Symantec Multiple Firewall TCP Options Denial of Service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108275582432246&w=2
Reference: MISC:http://www.eeye.com/html/Research/Upcoming/20040309.html
Reference: CONFIRM:http://www.symantec.com/avcenter/security/Content/2004.04.20.html
Reference: BID:9912
Reference: URL:http://www.securityfocus.com/bid/9912
Reference: SECTRACK:1009379
Reference: URL:http://securitytracker.com/id?1009379
Reference: SECTRACK:1009380
Reference: URL:http://securitytracker.com/id?1009380
Reference: XF:norton-firewalls-dos(15433)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15433
Reference: XF:symantec-firewall-tcp-dos(15936)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15936
 

Votes:

 

Name: CVE-2004-0376

 

Description:
oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.

Status: Candidate
Phase: Assigned (20040331)
Reference: GENTOO:GLSA-200403-08
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-08.xml
Reference: CONFIRM:http://www.time-travellers.org/oftpd/oftpd-dos.html
Reference: DEBIAN:DSA-473
Reference: URL:http://www.debian.org/security/2004/dsa-473
Reference: BID:9980
Reference: URL:http://www.securityfocus.com/bid/9980
Reference: SECUNIA:11220
Reference: URL:http://secunia.com/advisories/11220
Reference: XF:oftpd-port-dos(15622)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15622
 

Votes:

 

Name: CVE-2004-0377

 

Description:
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.

Status: Candidate
Phase: Assigned (20040331)
Reference: BUGTRAQ:20040405 [Full-Disclosure] iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108118694327979&w=2
Reference: FULLDISC:20040405 iDEFENSE Security Advisory 04.05.04: Perl win32_stat Function
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/019794.html
Reference: MISC:http://www.idefense.com/application/poi/display?id=93&type=vulnerabilities
Reference: CONFIRM:http://public.activestate.com/cgi-bin/perlbrowse?patch=22552
Reference: CERT-VN:VU#722414
Reference: URL:http://www.kb.cert.org/vuls/id/722414
Reference: XF:perl-win32stat-bo(15732)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15732
 

Votes:

 

Name: CVE-2004-0378

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040402)
 

Votes:

 

Name: CVE-2004-0379

 

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.

Status: Candidate
Phase: Assigned (20040402)
Reference: BUGTRAQ:20040405 Multiple XSS vulnerabilities in Microsoft SharePoint Portal Server 2001
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108118352303273&w=2
Reference: XF:sharepoint-portal-xss(15729)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15729
 

Votes:

 

Name: CVE-2004-0380

 

Description:
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

Status: Candidate
Phase: Assigned (20040405)
Reference: BUGTRAQ:20040219 Microsoft Internet Explorer Unspecified CHM File Processing Arbitrary Code Execution Vulnerability (bid 9658)
Reference: URL:http://www.securityfocus.com/archive/1/354447
Reference: BUGTRAQ:20040328 IE ms-its: and mk:@MSITStore: vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/358913
Reference: MISC:http://www.k-otik.net/bugtraq/02.18.InternetExplorer.php
Reference: MS:MS04-013
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx
Reference: CERT:TA04-104A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-104A.html
Reference: CERT:TA04-099A
Reference: CERT-VN:VU#323070
Reference: URL:http://www.kb.cert.org/vuls/id/323070
Reference: BID:9658
Reference: URL:http://www.securityfocus.com/bid/9658
Reference: BID:9105
Reference: URL:http://www.securityfocus.com/bid/9105
Reference: SECUNIA:10523
Reference: URL:http://secunia.com/advisories/10523
Reference: XF:outlook-mhtml-execute-code(15705)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15705
Reference: OVAL:oval:org.mitre.oval:def:1010
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1010
Reference: OVAL:oval:org.mitre.oval:def:1028
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1028
Reference: OVAL:oval:org.mitre.oval:def:882
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:882
Reference: OVAL:oval:org.mitre.oval:def:990
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:990
 

Votes:

 

Name: CVE-2004-0381

 

Description:
mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.

Status: Candidate
Phase: Assigned (20040405)
Reference: BUGTRAQ:20040324 mysqlbug tmpfile/symlink vulnerability.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108023246916294&w=2
Reference: DEBIAN:DSA-483
Reference: URL:http://www.debian.org/security/2004/dsa-483
Reference: GENTOO:GLSA-200405-20
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-20.xml
Reference: MANDRAKE:MDKSA-2004:034
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:034
Reference: REDHAT:RHSA-2004:569
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-569.html
Reference: REDHAT:RHSA-2004:597
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-597.html
Reference: BUGTRAQ:20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108206802810402&w=2
Reference: CIAC:P-018
Reference: URL:http://www.ciac.org/ciac/bulletins/p-018.shtml
Reference: BID:9976
Reference: URL:http://www.securityfocus.com/bid/9976
Reference: XF:mysql-mysqlbug-symlink(15617)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15617
 

Votes:

 

Name: CVE-2004-0382

 

Description:
Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.

Status: Candidate
Phase: Assigned (20040405)
Reference: CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00047.html
Reference: CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference: XF:macos-cups-configuration-unknown(15769)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15769
 

Votes:

 

Name: CVE-2004-0383

 

Description:
Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."

Status: Candidate
Phase: Assigned (20040405)
Reference: CONFIRM:http://lists.apple.com/mhonarc/security-announce/msg00047.html
Reference: CONFIRM:http://docs.info.apple.com/article.html?artnum=61798
Reference: XF:macos-mail-unknown(15768)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15768
 

Votes:

 

Name: CVE-2004-0384

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040406)
 

Votes:

 

Name: CVE-2004-0385

 

Description:
Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."

Status: Candidate
Phase: Assigned (20040406)
Reference: VULNWATCH:20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0078.html
Reference: BUGTRAQ:20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108144419001770&w=2
Reference: MISC:http://www.inaccessnetworks.com/ian/services/secadv01.txt
Reference: BUGTRAQ:20040316 new security alert #66 issued in Oracle web cache
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107945649127635&w=2
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf
Reference: CERT-VN:VU#413006
Reference: URL:http://www.kb.cert.org/vuls/id/413006
Reference: BID:9868
Reference: URL:http://www.securityfocus.com/bid/9868
Reference: OSVDB:4249
Reference: URL:http://www.osvdb.org/4249
Reference: SECUNIA:11118
Reference: URL:http://secunia.com/advisories/11118
Reference: XF:oracle-web-cache-vulnerabilities(15463)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15463
 

Votes:

 

Name: CVE-2004-0386

 

Description:
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.

Status: Candidate
Phase: Assigned (20040406)
Reference: BUGTRAQ:20040330 Heap overflow in MPlayer
Reference: URL:http://www.securityfocus.com/archive/1/359025
Reference: BUGTRAQ:20040330 MPlayer Security Advisory #002 - HTTP parsing vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108067020624076&w=2
Reference: CONFIRM:http://www.mplayerhq.hu/homepage/design6/news.html
Reference: GENTOO:GLSA-200403-13
Reference: URL:http://security.gentoo.org/glsa/glsa-200403-13.xml
Reference: MANDRAKE:MDKSA-2004:026
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:026
Reference: CERT-VN:VU#723910
Reference: URL:http://www.kb.cert.org/vuls/id/723910
Reference: BID:10008
Reference: URL:http://www.securityfocus.com/bid/10008
Reference: SECUNIA:11259
Reference: URL:http://secunia.com/advisories/11259
Reference: XF:mplayer-header-bo(15675)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15675
 

Votes:

 

Name: CVE-2004-0387

 

Description:
Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.

Status: Candidate
Phase: Assigned (20040409)
Reference: BUGTRAQ:20040307 REAL One Player R3T File Format Stack Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108135350810135&w=2
Reference: VULNWATCH:20040307 REAL One Player R3T File Format Stack Overflow
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0077.html
Reference: MISC:http://www.ngssoftware.com/advisories/realr3t.txt
Reference: CONFIRM:http://www.service.real.com/help/faq/security/040406_r3t/en/
Reference: BID:10070
Reference: URL:http://www.securityfocus.com/bid/10070
Reference: OSVDB:4977
Reference: URL:http://www.osvdb.org/displayvuln.php?osvdb_id=4977
Reference: SECUNIA:11314
Reference: URL:http://secunia.com/advisories/11314
Reference: XF:realplayer-r3t-bo(15774)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15774
 

Votes:

 

Name: CVE-2004-0388

 

Description:
The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.

Status: Candidate
Phase: Assigned (20040409)
Reference: CONFIRM:http://dev.mysql.com/doc/mysql/en/news-4-1-2.html
Reference: DEBIAN:DSA-483
Reference: URL:http://www.debian.org/security/2004/dsa-483
Reference: GENTOO:GLSA-200405-20
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-20.xml
Reference: MANDRAKE:MDKSA-2004:034
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:034
Reference: REDHAT:RHSA-2004:569
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-569.html
Reference: REDHAT:RHSA-2004:597
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-597.html
Reference: BUGTRAQ:20040414 [OpenPKG-SA-2004.014] OpenPKG Security Advisory (mysql)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108206802810402&w=2
Reference: CIAC:P-018
Reference: URL:http://www.ciac.org/ciac/bulletins/p-018.shtml
Reference: BID:10142
Reference: URL:http://www.securityfocus.com/bid/10142
Reference: OSVDB:6421
Reference: URL:http://www.osvdb.org/6421
Reference: SECTRACK:1009784
Reference: URL:http://securitytracker.com/id?1009784
Reference: SECUNIA:11223
Reference: URL:http://secunia.com/advisories/11223/
Reference: XF:mysql-mysqldmulti-symlink(15883)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15883
 

Votes:

 

Name: CVE-2004-0389

 

Description:
RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.

Status: Candidate
Phase: Assigned (20040409)
Reference: IDEFENSE:20040415 RealNetworks Helix Universal Server Denial of Service Vulnerability
Reference: URL:http://www.idefense.com/application/poi/display?id=102&type=vulnerabilities
Reference: BID:10157
Reference: URL:http://www.securityfocus.com/bid/10157
Reference: SECUNIA:11395
Reference: URL:http://secunia.com/advisories/11395
Reference: XF:helix-get-dos(15880)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15880
 

Votes:

 

Name: CVE-2004-0390

 

Description:
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.

Status: Candidate
Phase: Assigned (20040409)
Reference: FULLDISC:20040510 OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7 : X sessions which are not started by scologin cannot use the X authorization protocol
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html
Reference: SCO:SCOSA-2004.5
Reference: URL:http://www.securityfocus.com/advisories/6684
Reference: XF:openserver-x-session-insecure(16113)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16113
 

Votes:

 

Name: CVE-2004-0391

 

Description:
Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.

Status: Candidate
Phase: Assigned (20040409)
Reference: CISCO:20040407 A Default Username and Password in WLSE and HSE Devices
Reference: URL:http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml
Reference: CERT-VN:VU#659228
Reference: URL:http://www.kb.cert.org/vuls/id/659228
Reference: CIAC:O-111
Reference: URL:http://www.ciac.org/ciac/bulletins/o-111.shtml
Reference: BID:10076
Reference: URL:http://www.securityfocus.com/bid/10076
Reference: XF:cisco-default-password(15773)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15773
 

Votes:

 

Name: CVE-2004-0392

 

Description:
racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.

Status: Candidate
Phase: Assigned (20040413)
Reference: CONFIRM:http://www.vuxml.org/freebsd/40fcf20f-8891-11d8-90d1-0020ed76ef5a.html
Reference: CONFIRM:http://orange.kame.net/dev/query-pr.cgi?pr=555
Reference: SCO:SCOSA-2005.10
Reference: URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
Reference: XF:racoon-isakmp-dos(15893)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15893
 

Votes:

 

Name: CVE-2004-0393

 

Description:
Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.

Status: Candidate
Phase: Assigned (20040413)
Reference: BUGTRAQ:20040624 Rlpr Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108810992313652&w=2
Reference: DEBIAN:DSA-524
Reference: URL:http://www.debian.org/security/2004/dsa-524
Reference: BID:10578
Reference: URL:http://www.securityfocus.com/bid/10578
Reference: XF:rlpr-msg-format-string(16453)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16453
 

Votes:

 

Name: CVE-2004-0394

 

Description:
A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.

Status: Candidate
Phase: Assigned (20040413)
Reference: CONECTIVA:CLA-2004:846
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
Reference: DEBIAN:DSA-1070
Reference: URL:http://www.debian.org/security/2006/dsa-1070
Reference: DEBIAN:DSA-1067
Reference: URL:http://www.debian.org/security/2006/dsa-1067
Reference: DEBIAN:DSA-1069
Reference: URL:http://www.debian.org/security/2006/dsa-1069
Reference: DEBIAN:DSA-1082
Reference: URL:http://www.debian.org/security/2006/dsa-1082
Reference: GENTOO:GLSA-200407-02
Reference: URL:http://security.gentoo.org/glsa/glsa-200407-02.xml
Reference: MANDRAKE:MDKSA-2004:037
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:037
Reference: MLIST:[fedora-announce] 20040422 Fedora alert FEDORA-2004-111 (kernel)
Reference: URL:http://lwn.net/Articles/81773/
Reference: ENGARDE:ESA-20040428-004
Reference: URL:http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
Reference: SGI:20040504-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc
Reference: SGI:20040505-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc
Reference: SUSE:SuSE-SA:2004:010
Reference: URL:http://www.novell.com/linux/security/advisories/2004_10_kernel.html
Reference: BID:10233
Reference: URL:http://www.securityfocus.com/bid/10233
Reference: SECUNIA:20162
Reference: URL:http://secunia.com/advisories/20162
Reference: SECUNIA:20163
Reference: URL:http://secunia.com/advisories/20163
Reference: SECUNIA:20202
Reference: URL:http://secunia.com/advisories/20202
Reference: SECUNIA:20338
Reference: URL:http://secunia.com/advisories/20338
Reference: XF:linux-panic-bo(15953)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15953
 

Votes:

 

Name: CVE-2004-0395

 

Description:
The xatitv program in the gatos package does not properly drop root privileges when the configuration file does not exist, which allows local users to execute arbitrary commands via shell metacharacters in a system call.

Status: Candidate
Phase: Assigned (20040413)
Reference: DEBIAN:DSA-509
Reference: URL:http://www.debian.org/security/2004/dsa-509
Reference: BID:10437
Reference: URL:http://www.securityfocus.com/bid/10437
Reference: XF:gatos-xatitv-gain-privileges(16273)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16273
 

Votes:

 

Name: CVE-2004-0396

 

Description:
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.

Status: Candidate
Phase: Assigned (20040413)
Reference: BUGTRAQ:20040519 Advisory 07/2004: CVS remote vulnerability
Reference: URL:http://cert.uni-stuttgart.de/archive/bugtraq/2004/05/msg00219.html
Reference: FULLDISC:20040519 Advisory 07/2004: CVS remote vulnerability
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0980.html
Reference: MISC:http://security.e-matters.de/advisories/072004.html
Reference: CERT:TA04-147A
Reference: URL:http://www.us-cert.gov/cas/techalerts/TA04-147A.html
Reference: CERT-VN:VU#192038
Reference: URL:http://www.kb.cert.org/vuls/id/192038
Reference: OPENBSD:20040520 cvs server buffer overflow vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=openbsd-security-announce&m=108508894405639&w=2
Reference: DEBIAN:DSA-505
Reference: URL:http://www.debian.org/security/2004/dsa-505
Reference: FEDORA:FEDORA-2004-1620
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108636445031613&w=2
Reference: FREEBSD:FreeBSD-SA-04:10
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:10.cvs.asc
Reference: GENTOO:GLSA-200405-12
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-12.xml
Reference: MANDRAKE:MDKSA-2004:048
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:048
Reference: NETBSD:NetBSD-SA2004-008
Reference: URL:ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2004-008.txt.asc
Reference: REDHAT:RHSA-2004:190
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-190.html
Reference: SLACKWARE:SSA:2004-140-01
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.395865
Reference: SUSE:SuSE-SA:2004:013
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021742.html
Reference: BUGTRAQ:20040519 Advisory 07/2004: CVS remote vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108498454829020&w=2
Reference: BUGTRAQ:20040519 [OpenPKG-SA-2004.022] OpenPKG Security Advisory (cvs)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108500040719512&w=2
Reference: CIAC:O-147
Reference: URL:http://www.ciac.org/ciac/bulletins/o-147.shtml
Reference: BID:10384
Reference: URL:http://www.securityfocus.com/bid/10384
Reference: SECUNIA:11641
Reference: URL:http://secunia.com/advisories/11641
Reference: SECUNIA:11647
Reference: URL:http://secunia.com/advisories/11647
Reference: SECUNIA:11651
Reference: URL:http://secunia.com/advisories/11651
Reference: SECUNIA:11652
Reference: URL:http://secunia.com/advisories/11652
Reference: SECUNIA:11674
Reference: URL:http://secunia.com/advisories/11674
Reference: OSVDB:6305
Reference: URL:http://www.osvdb.org/6305
Reference: OVAL:oval:org.mitre.oval:def:970
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:970
Reference: XF:cvs-entry-line-bo(16193)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16193
 

Votes:

 

Name: CVE-2004-0397

 

Description:
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.

Status: Candidate
Phase: Assigned (20040413)
Reference: FULLDISC:20040519 Advisory 08/2004: Subversion remote vulnerability
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021737.html
Reference: BUGTRAQ:20040519 Advisory 08/2004: Subversion remote vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108498676517697&w=2
Reference: MISC:http://security.e-matters.de/advisories/082004.html
Reference: CONFIRM:http://subversion.tigris.org/svn-sscanf-advisory.txt
Reference: FEDORA:FEDORA-2004-128
Reference: URL:http://www.linuxsecurity.com/advisories/fedora_advisory-4373.html
Reference: FEDORA:FLSA:1748
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=1748
Reference: GENTOO:GLSA-200405-14
Reference: URL:http://www.gentoo.org/security/en/glsa/glsa-200405-14.xml
Reference: BUGTRAQ:20040519 [OpenPKG-SA-2004.023] OpenPKG Security Advisory (subversion)
Reference: URL:http://www.securityfocus.com/archive/1/363814
Reference: BID:10386
Reference: URL:http://www.securityfocus.com/bid/10386
Reference: OSVDB:6301
Reference: URL:http://www.osvdb.org/6301
Reference: SECUNIA:11642
Reference: URL:http://secunia.com/advisories/11642
Reference: SECUNIA:11675
Reference: URL:http://secunia.com/advisories/11675
Reference: XF:subversion-date-parsing-command-execution(16191)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16191
 

Votes:

 

Name: CVE-2004-0398

 

Description:
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.

Status: Candidate
Phase: Assigned (20040413)
Reference: BUGTRAQ:20040519 Advisory 06/2004: libneon date parsing vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108498433632333&w=2
Reference: FULLDISC:20040519 Advisory 06/2004: libneon date parsing vulnerability
Reference: URL:http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html
Reference: CONECTIVA:CLA-2004:841
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000841
Reference: REDHAT:RHSA-2004:191
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-191.html
Reference: DEBIAN:DSA-506
Reference: URL:http://www.debian.org/security/2004/dsa-506
Reference: DEBIAN:DSA-507
Reference: URL:http://www.debian.org/security/2004/dsa-507
Reference: FEDORA:FEDORA-2004-1552
Reference: URL:https://bugzilla.fedora.us/show_bug.cgi?id=1552
Reference: GENTOO:GLSA-200405-13
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-13.xml
Reference: GENTOO:GLSA-200405-15
Reference: URL:http://security.gentoo.org/glsa/glsa-200405-15.xml
Reference: MANDRAKE:MDKSA-2004:049
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:049
Reference: BUGTRAQ:20040519 [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108500057108022&w=2
Reference: CIAC:O-148
Reference: URL:http://www.ciac.org/ciac/bulletins/o-148.shtml
Reference: BID:10385
Reference: URL:http://www.securityfocus.com/bid/10385
Reference: OSVDB:6302
Reference: URL:http://www.osvdb.org/6302
Reference: SECUNIA:11638
Reference: URL:http://secunia.com/advisories/11638
Reference: SECUNIA:11650
Reference: URL:http://secunia.com/advisories/11650
Reference: SECUNIA:11673
Reference: URL:http://secunia.com/advisories/11673
Reference: XF:neon-library-nerfc1036parse-bo(16192)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16192
 

Votes:

 

Name: CVE-2004-0399

 

Description:
Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.

Status: Candidate
Phase: Assigned (20040413)
Reference: FULLDISC:20040506 Buffer overflows in exim, yet still exim much better than windows
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html
Reference: MISC:http://www.guninski.com/exim1.html
Reference: DEBIAN:DSA-501
Reference: URL:http://www.debian.org/security/2004/dsa-501
Reference: DEBIAN:DSA-502
Reference: URL:http://www.debian.org/security/2004/dsa-502
Reference: SECUNIA:11558
Reference: URL:http://secunia.com/advisories/11558
Reference: XF:exim-requireverify-bo(16079)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16079
 

Votes:

 

Name: CVE-2004-0400

 

Description:
Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.

Status: Candidate
Phase: Assigned (20040413)
Reference: FULLDISC:20040506 Buffer overflows in exim, yet still exim much better than windows
Reference: URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021015.html
Reference: MISC:http://www.guninski.com/exim1.html
Reference: DEBIAN:DSA-501
Reference: URL:http://www.debian.org/security/2004/dsa-501
Reference: DEBIAN:DSA-502
Reference: URL:http://www.debian.org/security/2004/dsa-502
Reference: XF:exim-headerschecksyntax-bo(16077)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16077
 

Votes:

 

Name: CVE-2004-0401

 

Description:
Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.

Status: Candidate
Phase: Assigned (20040413)
Reference: CONFIRM:http://packages.debian.org/changelogs/pool/main/libt/libtasn1-2/libtasn1-2_0.2.13-1/changelog
Reference: MISC:http://www.backports.org/changelog.html
Reference: BID:10360
Reference: URL:http://www.securityfocus.com/bid/10360
Reference: OSVDB:15126
Reference: URL:http://www.osvdb.org/15126
Reference: SECTRACK:1010159
Reference: URL:http://securitytracker.com/id?1010159
Reference: XF:libtasn1-der-parsing(16157)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16157
 

Votes:

 

Name: CVE-2004-0402

 

Description:
Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.

Status: Candidate
Phase: Assigned (20040413)
Reference: DEBIAN:DSA-508
Reference: URL:http://www.debian.org/security/2004/dsa-508
Reference: MANDRAKE:MDKSA-2004:053
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:053
Reference: XF:xpcd-svga-pcdopen-bo(16236)
Reference: URL:http://xforce.iss.net/xforce/xfdb/16236
Reference: BID:10403
Reference: URL:http://www.securityfocus.com/bid/10403
 

Votes:

 

Name: CVE-2004-0403

 

Description:
Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.

Status: Candidate
Phase: Assigned (20040413)
Reference: CONFIRM:http://www.vuxml.org/freebsd/ccd698df-8e20-11d8-90d1-0020ed76ef5a.html
Reference: CONFIRM:http://www.kame.net/dev/cvsweb2.cgi/kame/kame/kame/racoon/isakmp.c.diff?r1=1.180&r2=1.181
Reference: CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=232288
Reference: APPLE:APPLE-SA-2004-05-03
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108369640424244&w=2
Reference: GENTOO:GLSA-200404-17
Reference: URL:http://security.gentoo.org/glsa/glsa-200404-17.xml
Reference: MANDRAKE:MDKSA-2004:069
Reference: URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:069
Reference: REDHAT:RHSA-2004:165
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-165.html
Reference: SCO:SCOSA-2005.10
Reference: URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
Reference: SGI:20040506-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040506-01-U.asc
Reference: BID:10172
Reference: URL:http://www.securityfocus.com/bid/10172
Reference: OSVDB:5491
Reference: URL:http://www.osvdb.org/5491
Reference: OVAL:oval:org.mitre.oval:def:984
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:984
Reference: SECTRACK:1009937
Reference: URL:http://securitytracker.com/id?1009937
Reference: SECUNIA:11410
Reference: URL:http://secunia.com/advisories/11410
Reference: SECUNIA:11877
Reference: URL:http://secunia.com/advisories/11877
Reference: XF:racoon-isakmp-dos(15893)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15893
 

Votes:

 

Name: CVE-2004-0404

 

Description:
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.

Status: Candidate
Phase: Assigned (20040414)
Reference: DEBIAN:DSA-488
Reference: URL:http://www.debian.org/security/2004/dsa-488
Reference: MANDRAKE:MDKSA-2004:155
Reference: URL:http://www.mandriva.com/security/advisories?name=MDKSA-2004:155
Reference: BID:10162
Reference: URL:http://www.securityfocus.com/bid/10162
Reference: SECUNIA:11399
Reference: URL:http://secunia.com/advisories/11399
Reference: XF:logcheck-directory-symlink(15888)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15888
 

Votes:

 

Name: CVE-2004-0405

 

Description:
CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.

Status: Candidate
Phase: Assigned (20040416)
Reference: DEBIAN:DSA-486
Reference: URL:http://www.debian.org/security/2004/dsa-486
Reference: FREEBSD:FreeBSD-SA-04:07
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:07.cvs.asc
Reference: FEDORA:FEDORA-2004-1620
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108636445031613&w=2
Reference: GENTOO:GLSA-200404-13
Reference: URL:http://security.gentoo.org/glsa/glsa-200404-13.xml
Reference: SGI:20040404-01-U
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
Reference: SLACKWARE:SSA:2004-108-02
Reference: URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.400181
Reference: OVAL:oval:org.mitre.oval:def:1060
Reference: URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1060
Reference: XF:cvs-dotdot-directory-traversal(15891)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15891
 

Votes:

 

Name: CVE-2004-0406

 

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Status: Candidate
Phase: Assigned (20040416)
 

Votes:

 

Name: CVE-2004-0407

 

Description:
The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.

Status: Candidate
Phase: Assigned (20040416)
Reference: BUGTRAQ:20040416 [securityzone@macromedia.com: New Macromedia Security Zone Bulletin Posted]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108213782629001&w=2
Reference: CONFIRM:http://www.macromedia.com/devnet/security/security_zone/mpsb04-06.html
Reference: BID:10158
Reference: URL:http://www.securityfocus.com/bid/10158
Reference: OSVDB:5402
Reference: URL:http://www.osvdb.org/5402
Reference: SECTRACK:1009825
Reference: URL:http://securitytracker.com/id?1009825
Reference: SECUNIA:11392
Reference: URL:http://secunia.com/advisories/11392
Reference: XF:coldfusion-upload-file-dos(15882)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15882
 

Votes:

 

Name: CVE-2004-0408

 

Description:
Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.

Status: Candidate
Phase: Assigned (20040416)
Reference: DEBIAN:DSA-494
Reference: URL:http://www.debian.org/security/2004/dsa-494
Reference: BID:10192
Reference: URL:http://www.securityfocus.com/bid/10192
Reference: XF:ident2-childservice-bo(15938)
Reference: URL:http://xforce.iss.net/xforce/xfdb/15938
 

Votes:

 

Name: CVE-2004-0409

 

Description:
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

Status: Candidate
Phase: Assigned (20040416)
Reference: MLIST:[xchat-announce] 20040405 xchat 2.0.x Socks5 Vulnerability
Reference: URL:http://mail.nl.linux.org/xchat-announce/2004-04/msg00000.html
Reference: CONFIRM:http://www.xchat.org/
Reference: DEBIAN:DSA-493
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108258002427226&w=2
Reference: FEDORA:FLSA:123013
Reference: URL:http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_123013
Reference: REDHAT:RHSA-2004:177
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-177.html
Reference: REDHAT:RHSA-2004:585
Reference: URL:http://www.redhat.com/support/errata/RHSA-2004-585.html
Reference: GENTOO:GLSA-200404-15
Reference: URL:http://security.gentoo.org/glsa/glsa-200404-15.xml
 

Votes:

 

Name: CVE-2004-0410

 

Description:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Status: Candidate
Phase: Assigned (20040416)
 

Votes:

 

Name: CVE-2004-0411

 

Descrip