CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4037  CVE-2001-1233  Candidate  Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4042  CVE-2001-1238  Candidate  Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REJECT(1) Baker | REVIEWING(1) Wall  Baker> I don"t think this is really a vulnerability. If I am not mistaken, | those are "services" which have to be managed by the services control | in windows 2K. This keeps users from killing things the system has | to have. I don"t think it is possible to kill another of other services | in this manner either. Try it on almost any W2K system, and there are any | number of services that you cannot kill from the process tab, rather you | must go to the services controller to stop the service. | I vote to reject this, as this is not a vulnerability, since you would have | to be administrator on the system to change one of these services to a trojan | version anyway.  View
4043  CVE-2001-1239  Candidate  PowerNet IX allows remote attackers to cause a denial of service via a port scan.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:powernet-ix-portscan-dos(9994)  View
4045  CVE-2001-1241  Candidate  Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4046  CVE-2001-1242  Candidate  Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View

Page 144 of 20943, showing 5 records out of 104715 total, starting on record 716, ending on 720

Actions