CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4869  CVE-2002-0477  Candidate  Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.  Proposed (20020611)  ACCEPT(5) Baker, Cole, Frech, Green, Wall | NOOP(2) Cox, Foat | REVIEWING(1) Christey  Christey> Is swf_clear.html *really* related to standalone_update.htm? | Or is the former really talking about a third issue related to | a virus? standalone_update.htm is clearly fscommand ("exec"). | It has an "Additional information" statement that says: | "For a description of the potential issue with the previous | stand-alone player, please refer to [swf_clear.htm]" | | I interpret "the previous stand-alone player" as meaning "the player | that we are updating with this advisory." Since we know that | standalone_update.htm is exec, this implies that swf_clear.htm is | really the exec issue. However, swf_clear.html doesn"t | mention fscommand ("exec") AT ALL, which casts doubt or at | least uncertainty as to my conclusions. | | swf_clear.html links back to standalone_update.htm, so at | least the references are circular. | | At least it"s pretty clear that this issue is different from | CVE-2002-0476. | | Email inquiry sent to Macromedia on June 13, 2002.  View
2578  CVE-2000-1009  Candidate  dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.  Proposed (20001129)  ACCEPT(5) Baker, Cole, Frech, Mell, Renaud | NOOP(1) Christey  Christey> http://www.redhat.com/support/errata/RHSA-2000-100.html | ADDREF BUGTRAQ:20001103 Trustix Security Advisory - dump | http://archives.neohapsis.com/archives/bugtraq/2000-11/0026.html | Christey> CERT-VN:VU#153653 | URL:http://www.kb.cert.org/vuls/id/153653  View
3259  CVE-2001-0441  Candidate  Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.  Proposed (20010524)  ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(1) Wall    View
3275  CVE-2001-0458  Candidate  Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.  Proposed (20010524)  ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(1) Wall    View
3267  CVE-2001-0450  Candidate  Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.  Proposed (20010524)  ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(2) Christey, Wall  Christey> Change "LIST" to "DIR" - see original post. The problem with | LIST (and NLST) occurred in Broker 3.0, not 5.0. | | The CONFIRM link is dead. | | Thanks to John Segura of secureinfo.com for noticing this.  View

Page 1069 of 20943, showing 5 records out of 104715 total, starting on record 5341, ending on 5345

Actions