CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3828  CVE-2001-1024  Candidate  login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall  CHANGE> [Green changed vote from REVIEWING to ACCEPT]  View
3829  CVE-2001-1025  Candidate  PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:php-nuke-prefix-admin-access(6945)  View
3837  CVE-2001-1033  Candidate  Compaq TruCluster 1.5 allows remote attackers to cause a denial of service via a port scan from a system that does not have a DNS PTR record, which causes the cluster to enter a "split-brain" state.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3838  CVE-2001-1034  Candidate  Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall  Christey> Acknowledged in: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | Vendor says problem affects all versions "prior to 4.1.3" | Christey> Confirmed by vendor: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | | Also affects OSes other than FreeBSD. | DEBIAN:DSA-148 | URL:http://www.debian.org/security/2002/dsa-148 | Christey> MANDRAKE:MDKSA-2002:055  View
3614  CVE-2001-0808  Candidate  gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.  Proposed (20011122)  ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(3) Armstrong, Foat, Wall  Bishop> If the SPECIFIC nature of the problem is determined to be both, I would | accept two separate candidates. But in the absence of this information, | I favor accepting it now rather than waiting for details. We can always | revisit it later.  View

Page 192 of 20943, showing 5 records out of 104715 total, starting on record 956, ending on 960

Actions