CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3661 | CVE-2001-0855 | Candidate | Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable. | Modified (20050703) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:clearcase-dbloader-term-bo(7488) | View |
3662 | CVE-2001-0856 | Candidate | Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key. | Modified (20050703) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:cca-3des-weak-key(7491) | View |
2404 | CVE-2000-0835 | Candidate | search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter. | Modified (20100115) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Collins, Wall | REJECT(2) Baker, Magdych | Magdych> Unless the beta product is in very widespread use, or the product is in | "perpetual beta" (e.g. ICQ), I would prefer not to include beta software. | Christey> XF:sambar-search-view-folder | Frech> XF:sambar-search-view-folder(5247) | Baker> Unless we change our CD:EX-BETA, we should reject this entry. Perhaps we need to address the issue of Beta software again, but the previous discussion was pretty thorough and I believe the editorial board was unanimous in excluding normal beta software. | Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar" | View |
5363 | CVE-2002-0975 | Candidate | Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. | Modified (20071101) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall | Christey> ADDREF MS:MS02-066 - "the patch sets the Kill Bit on a legacy | DirectX ActiveX control which has been retired but which has a | security vulnerability." | ADDREF MSKB:Q810202 - deals with "a security vulnerability | that exists in the DirectX Files Viewer control (Xweb.ocx)" | | Thanks to Andrew G. Tereschenko (the researcher) for this | additional information. | Frech> XF:ms-directx-files-viewer-bo(9877) | Christey> fix typo: "execute arbitrary [CODE]" | View |
3587 | CVE-2001-0780 | Candidate | Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter. | Proposed (20011012) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:directory-pro-directory-traversal(6632) | All references point to CGI with the name of | directorypro.cgi, not cosmicpro.cgi as listed in description. | Christey> Not sure how cosmicpro.cgi got in there. It should be | directorypro.cgi as indicated by Andre. | View |
Page 1147 of 20943, showing 5 records out of 104715 total, starting on record 5731, ending on 5735