CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3309 | CVE-2001-0492 | Candidate | Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3. | Modified (20030619-02) | ACCEPT(4) Baker, Balinsky, Cole, Oliver | MODIFY(1) Frech | NOOP(4) Christey, Wall, Williams, Ziese | CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT] | Balinsky> Vendor acknowledged the problem in a personal communication. | Frech> XF:netcruiser-server-path-disclosure(6468) | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> Fix typo (accidental URL insertion) in XF reference | View |
2966 | CVE-2001-0145 | Candidate | Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field. | Proposed (20010404) | ACCEPT(4) Baker, Balinsky, Cole, Wall | MODIFY(1) Frech | REVIEWING(3) Bishop, Christey, Ziese | Christey> In a post to Bugtraq, Joel Moses notes that this is a | duplicate of CVE-2000-0756: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Balinsky> It seems that this is a more specific case of | CVE-2000-0756. The reference for 2000-0756 states that there is a | buffer overflow in the birthday AND the e-mail field, as well as other | suspected fields. As this current candidate only addresses the | birthday field, it seems that there are likely different lines of code | involved. | Microsoft is not specific about what specifically the patch | addresses. It is possible that the other overflows in 2000-0756 are | still vulnerable and that the @stake group just didn"t bother to test | them. | We will not know the answer until someone retests those other | fields to see if they are still vulnerable. | If they are, then 2000-0756 might deserve being split up. | Frech> XF:outlook-vcard-dos(5175) | Christey> Consider adding BID:2459 | View |
3072 | CVE-2001-0251 | Candidate | The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command. | Proposed (20010404) | ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(2) Wall, Ziese | CHANGE> [Bishop changed vote from REVIEWING to ACCEPT] | View |
3071 | CVE-2001-0250 | Candidate | The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command. | Proposed (20010404) | ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(2) Wall, Ziese | Bishop> This is a problem if the policy says it is. It may not be a security | problem in general, though. I voted accept because it may be a problem. | View |
3614 | CVE-2001-0808 | Candidate | gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter. | Proposed (20011122) | ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(3) Armstrong, Foat, Wall | Bishop> If the SPECIFIC nature of the problem is determined to be both, I would | accept two separate candidates. But in the absence of this information, | I favor accepting it now rather than waiting for details. We can always | revisit it later. | View |
Page 1013 of 20943, showing 5 records out of 104715 total, starting on record 5061, ending on 5065