CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4524 | CVE-2002-0130 | Candidate | Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
4013 | CVE-2001-1209 | Candidate | Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey | Christey> INCLUSION: The author of the zml.cgi program says that the vulnerable | version is not his, and that zml.cgi does not take a file parameter. | If this is an adaptation of that zml.cgi program, and the adaptation | is not generally available, then it should not be included in CVE. | Almost all of the hits on Google for "zml.cgi" are references to the | reported vulnerability, and a search for "zml" doesn"t turn up any | obvious web pages, so it cannot be determined if there is another | product that happens to use a script named zml.cgi. | View |
4526 | CVE-2002-0132 | Candidate | Buffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
4015 | CVE-2001-1211 | Candidate | Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View | |
4527 | CVE-2002-0133 | Candidate | Buffer overflows in Avirt Gateway Suite 4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long header fields to the HTTP proxy, or (2) a long string to the telnet proxy. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View |
Page 171 of 20943, showing 5 records out of 104715 total, starting on record 851, ending on 855