CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3537  CVE-2001-0729  Candidate  Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.  Modified (20071115)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View
3554  CVE-2001-0747  Candidate  Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request.  Proposed (20011012)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:netscape-enterprise-uri-bo(6554) | Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE.  View
4584  CVE-2002-0192  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0193, CVE-2002-1564. Reason: This candidate was published with a description that identified a different vulnerability than what was identified in the original authoritative reference. Notes: Consult CVE-2002-0193 or CVE-2002-1564 to find the identifier for the proper issue.  Modified (20050204)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Cox | REJECT(1) Christey  Frech> XF:ie-content-disposition-variant(9085) | Christey> Hrmmm... the MS advisory says this is the "Script within | Cookies Reading Cookies" vulnerability... This description | was also used for CVE-2002-0193. | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> This CAN had the wrong description added to it, which made | it look like a different vulnerability than the one identified | by Microsoft in MS:MS02-023. Therefore this CAN should be | REJECTed.  View
4581  CVE-2002-0189  Candidate  Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.  Modified (20061101)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Christey  Christey> NOTE: As of 5/20/2002, there is a lack of clarity regarding | the details of this vulnerability and other vulnerabilities | being reported by GreyMagic and Thor Larholm. Additional | details will be added to this candidate if/when they become | available. This candidate is solely for the issue that is | being addressed by Microsoft in MS:MS02-023. Its relationship | with other reported issues is currently unproven. | | This candidate is subject to CD:VAGUE. | Christey> XF:ie-dialog-window-css(8868) | URL:http://www.iss.net/security_center/static/8868.php | Frech> XF:ie-dialog-window-css(8868) | Baker> I agree some of the information appears vague, but seems to be legitimate.  View
5242  CVE-2002-0852  Candidate  Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.  Proposed (20020830)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> "allows" should be "allow" | Christey> CERT-VN:VU#287771 | URL:http://www.kb.cert.org/vuls/id/287771 | XF:cisco-vpn-spi-bo(9819) | URL:http://www.iss.net/security_center/static/9819.php | XF:cisco-vpn-ike-payload-bo(9820) | URL:http://www.iss.net/security_center/static/9820.php | BID:5441 | URL:http://www.securityfocus.com/bid/5441 | BID:5443 | URL:http://www.securityfocus.com/bid/5443 | Frech> XF:cisco-vpn-spi-bo(9819) | XF:cisco-vpn-ike-payload-bo(9820)  View

Page 1058 of 20943, showing 5 records out of 104715 total, starting on record 5286, ending on 5290

Actions