CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8190  CVE-2003-1366  Candidate  chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.  Assigned (20071016)  None (candidate not yet proposed)    View
8189  CVE-2003-1365  Candidate  The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.  Assigned (20071016)  None (candidate not yet proposed)    View
8188  CVE-2003-1364  Candidate  Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.  Assigned (20071016)  None (candidate not yet proposed)    View
8187  CVE-2003-1363  Candidate  The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.  Assigned (20071016)  None (candidate not yet proposed)    View
8186  CVE-2003-1362  Candidate  Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.  Assigned (20071016)  None (candidate not yet proposed)    View

Page 19306 of 20943, showing 5 records out of 104715 total, starting on record 96526, ending on 96530

Actions