CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3114  CVE-2001-0293  Candidate  Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.  Proposed (20010404)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:ftpxq-directory-traversal(6166) | Christey> Email inquiry sent to support@datawizard.net on March 10, 2002. | Christey> Acknowledgement received from rmawji@datawizard.net on March | 11, 2002: "that was fixed in the next version (2.0.94)."  View
3123  CVE-2001-0302  Candidate  Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.  Proposed (20010404)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:pi3web-isapi-bo(6113) | Christey> CONFIRM:http://sourceforge.net/tracker/index.php?func=detail&aid=410354&group_id=17753&atid=117753  View
3209  CVE-2001-0391  Candidate  Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:xitami-server-dos(6389) | Christey> Consider adding BID:2622  View
3237  CVE-2001-0419  Candidate  Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:oracle-appserver-ndwfn4-bo(6334) | Christey> At http://otn.oracle.com/deploy/security/alerts.htm, | in an item titled "Oracle Application Server Buffer Overflow," | Oracle says that it was "Unable to reproduce vulnerability"  View
5398  CVE-2002-1010  Candidate  Lotus Domino R4 allows remote attackers to bypass access restrictions for files in the web root via an HTTP request appended with a "?" character, which is treated as a wildcard character and bypasses the web handlers.  Proposed (20020830)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:lotus-domino-url-bypass(10386)  View

Page 1141 of 20943, showing 5 records out of 104715 total, starting on record 5701, ending on 5705

Actions