CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3638 | CVE-2001-0832 | Candidate | Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability." | Proposed (20011122) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:oracle-binary-symlink(6940) | Christey> Possible dupe with CVE-2001-1041; need to review more closely. | View |
3627 | CVE-2001-0821 | Candidate | The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt. | Proposed (20011122) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Frech | NOOP(2) Foat, Wall | View | |
3641 | CVE-2001-0835 | Candidate | Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup. | Modified (20020226-01) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:webalizer-html-tag-host(7350) | XF:webalizer-html-tags-keywords(7351) | Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat) | Christey> CONECTIVA:CLA-2001:435 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435 | View |
1781 | CVE-2000-0203 | Candidate | The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345. | Proposed (20000322) | ACCEPT(5) Armstrong, Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Ozancin | Frech> XF:trendmicro-tmlisten-dos | View |
5224 | CVE-2002-0834 | Candidate | Buffer overflow in the ISIS dissector for Ethereal 0.9.5 and earlier allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets. | Proposed (20020830) | ACCEPT(5) Armstrong, Baker, Cole, Cox, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> BUGTRAQ:20020830 GLSA: ethereal | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103072249023973&w=2 | Christey> DEBIAN:DSA-162 | URL:http://www.debian.org/security/2002/dsa-162 | Christey> XF:ethereal-isis-dissector-bo(9942) | URL:http://www.iss.net/security_center/static/9942.php | Frech> XF:ethereal-isis-dissector-bo(9942) | Christey> REDHAT:RHSA-2002:036 | URL:http://www.redhat.com/support/errata/RHSA-2002-036.html | View |
Page 1054 of 20943, showing 5 records out of 104715 total, starting on record 5266, ending on 5270