CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4699 | CVE-2002-0307 | Candidate | Directory traversal vulnerability in ans.pl in Avenger"s News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl"s eval function. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:ans-plugin-execute-commands(8256) | View |
4703 | CVE-2002-0311 | Candidate | Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi. | Proposed (20020502) | ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4704 | CVE-2002-0312 | Candidate | Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. | Proposed (20020502) | ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4706 | CVE-2002-0314 | Candidate | fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. | Proposed (20020502) | ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | View | |
4707 | CVE-2002-0315 | Candidate | fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. | Proposed (20020502) | ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | View |
Page 136 of 20943, showing 5 records out of 104715 total, starting on record 676, ending on 680