CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2935  CVE-2001-0114  Candidate  statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.  Proposed (20010214)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:omnihttpd-statsconfig-corrupt-files | URL:http://xforce.iss.net/static/5955.php | Frech> XF:omnihttpd-statsconfig-corrupt-files(5955) | Christey> MISC:http://www.omnicron.ca/httpd/docs/release.html | May be vague acknowledgement; need to ask | mailto:support@omnicron.ca?subject=OmniHTTPd Technical Support | (and ask them about the other OmniHTTP issues as well)  View
2948  CVE-2001-0127  Candidate  Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.  Modified (20050509)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:flash-module-bo | Frech> XF:flash-module-bo(5952)  View
2953  CVE-2001-0132  Candidate  Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.  Proposed (20010214)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:interscan-viruswall-symlink | URL:http://xforce.iss.net/static/5947.php | Frech> XF:interscan-viruswall-symlink(5947)  View
2956  CVE-2001-0135  Candidate  The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.  Proposed (20010214)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:ultraboard-cgi-perm | URL:http://xforce.iss.net/static/5931.php | Frech> XF:ultraboard-cgi-perm(5931) | In description, "writeable": from | http://www.dictionary.com/cgi-bin/dict.pl?term=Writable: Writable | Writ"a*ble, a. Capable of, or suitable for, being written down. | Christey> Yeah yeah yeah, Andre, I knew you"d catch my bad spelling :-)  View
3047  CVE-2001-0226  Candidate  Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers tor ead arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.  Proposed (20010309)  MODIFY(1) Frech | NOOP(3) Christey, Lawler, Ziese  Frech> XF:biblioweb-directory-traversal(6066) | Christey> fix typo: "tor ead"  View

Page 1107 of 20943, showing 5 records out of 104715 total, starting on record 5531, ending on 5535

Actions