CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3828 | CVE-2001-1024 | Candidate | login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall | CHANGE> [Green changed vote from REVIEWING to ACCEPT] | View |
3829 | CVE-2001-1025 | Candidate | PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php. | Proposed (20020131) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:php-nuke-prefix-admin-access(6945) | View |
3837 | CVE-2001-1033 | Candidate | Compaq TruCluster 1.5 allows remote attackers to cause a denial of service via a port scan from a system that does not have a DNS PTR record, which causes the cluster to enter a "split-brain" state. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
3838 | CVE-2001-1034 | Candidate | Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall | Christey> Acknowledged in: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | Vendor says problem affects all versions "prior to 4.1.3" | Christey> Confirmed by vendor: | BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed | URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html | | Also affects OSes other than FreeBSD. | DEBIAN:DSA-148 | URL:http://www.debian.org/security/2002/dsa-148 | Christey> MANDRAKE:MDKSA-2002:055 | View |
3614 | CVE-2001-0808 | Candidate | gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter. | Proposed (20011122) | ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(3) Armstrong, Foat, Wall | Bishop> If the SPECIFIC nature of the problem is determined to be both, I would | accept two separate candidates. But in the absence of this information, | I favor accepting it now rather than waiting for details. We can always | revisit it later. | View |
Page 192 of 20943, showing 5 records out of 104715 total, starting on record 956, ending on 960