CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2743  CVE-2000-1176  Candidate  Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.  Proposed (20001219)  MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:yabb-search-format-string(5501)  View
1866  CVE-2000-0288  Candidate  Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.  Proposed (20000426)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REJECT(1) Baker | REVIEWING(2) Christey, Levy  Frech> XF:http-cgi-infonautics-getdoc | Christey> CD:EX-ONLINE-SVC applies here. This may be a vulnerability in | an online service (the search engines used by Infonautics) | which poses no risk to anyone but the company itself.  View
1479  CVE-1999-1499  Candidate  named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.  Proposed (20010912)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REJECT(1) Foat  Foat> The files get written to /var/named which the user does not have write | access. | Frech> XF:bind-sigint-sigiot-symlink(7366)  View
3215  CVE-2001-0397  Candidate  Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese  Frech> XF:silent-runner-helo-bo(6309) | In description, product is called SilentRunner (no space). | See http://www.silentrunner.com/index.html.  View
3228  CVE-2001-0410  Candidate  Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese  Frech> XF:virusbuster-mua-bo(6034) | Possible | CONFIRM:http://www.securityfocus.com/archive/1/173231, but Trend URL | in message was currently down. | Possible close-match or duplicate with CVE-2001-0174 (most likely | this is a level-of-abstraction issue).  View

Page 1102 of 20943, showing 5 records out of 104715 total, starting on record 5506, ending on 5510

Actions