CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3886  CVE-2001-1082  Candidate  Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20020131)  ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Christey | NOOP(2) Foat, Wall | REJECT(1) Frech  Frech> Reference no longer exists, and has no title for cross | reference. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> Dead reference; will reconsider revote if valid reference | presented. | Christey> MISC:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html  View
3676  CVE-2001-0870  Candidate  HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.  Proposed (20020131)  NOOP(4) Armstrong, Cole, Foat, Wall    View
3698  CVE-2001-0892  Candidate  Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.  Proposed (20020131)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:httpd-bypass-permissions(7541) | Christey> CONECTIVA:CLA-2003:777  View
3703  CVE-2001-0897  Candidate  Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.  Proposed (20020131)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Armstrong, Foat, Wall  Frech> XF:ultimatebb-cookie-gain-privileges(6142) | Is this a variant of the following references: | BugTraq Mailing List, Wed Feb 21 2001 13:19:16 Ultimate Bulletin | Board, http://online.securityfocus.com/archive/1/164583 | BugTraq Mailing List, Wed Feb 21 2001 17:59:13 Re: Ultimate Bulletin | Board, http://online.securityfocus.com/archive/1/164716  View
3714  CVE-2001-0908  Candidate  CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).  Proposed (20020131)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View

Page 180 of 20943, showing 5 records out of 104715 total, starting on record 896, ending on 900

Actions