CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1440  CVE-1999-1460  Candidate  BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.  Proposed (20010912)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Foat, Wall  Frech> XF:patrol-snmp-file-creation(2347) | Christey> The vendor has acknowledged this vulnerability via e-mail. It | has been fixed. | | NOTE: despite the fact that this candidate has been acknowledged | and fixed by the vendor, it is affected by the CVE content | decision CD:SF-LOC. It cannot be accepted until the | CD:SF-LOC guidelines have been finalized.  View
3032  CVE-2001-0211  Candidate  Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.  Proposed (20010309)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Lawler, Ziese  Frech> XF:webspirs-cgi-view-files(6101) | Christey> ADDREF BUGTRAQ:20010331 Webspirs remote script explotation | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98608561912120&w=2 | Christey> Mention the webspirs.cgi program specifically; also, should | the version be 3.3.1?  View
2295  CVE-2000-0719  Candidate  VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.  Proposed (20000921)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy  Christey> XF:varicad-world-write-permissions | http://xforce.iss.net/static/5077.php | Frech> XF:aricad-world-write-permissions(5077) | Christey> BID:1862  View
3198  CVE-2001-0380  Candidate  Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string "ILMI".  Modified (20090302)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:cisco-ios-modify-snmp(6169) | Christey> Fix the date of the Bugtraq post | Christey> The Bugtraq poster didn"t provide many details, but said that | the vendor was out of business. It"s possible that this ILMI | community string has no relationship with the Cisco ILMI | problem, in which case this should remain a separate CAN. | Christey> Further research suggests that ILMI is a standard | specification for ATM, and therefore this CAN should remain split from | the Cisco ILMI problem (CVE-2001-0711).  View
3238  CVE-2001-0420  Candidate  Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547  View

Page 1139 of 20943, showing 5 records out of 104715 total, starting on record 5691, ending on 5695

Actions