CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3633 | CVE-2001-0827 | Candidate | Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests. | Proposed (20011122) | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | REJECT(1) Frech | Frech> See XF:cerberus-ftp-bo(6728). May also be a dupe with | BID:2901. | View |
3635 | CVE-2001-0829 | Candidate | A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message. | Proposed (20011122) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall | Frech> XF:java-servlet-crosssite-scripting(6793) | Christey> CERT-VN:VU#672683 | URL:http://www.kb.cert.org/vuls/id/672683 | View |
3638 | CVE-2001-0832 | Candidate | Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability." | Proposed (20011122) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:oracle-binary-symlink(6940) | Christey> Possible dupe with CVE-2001-1041; need to review more closely. | View |
3644 | CVE-2001-0838 | Candidate | Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers execute arbitrary code via format string specifiers in the -soa command. | Proposed (20011122) | ACCEPT(2) Armstrong, Baker | MODIFY(1) Frech | NOOP(5) Bishop, Christey, Cole, Foat, Wall | Frech> XF:rwhoisd-remote-format-string(7353) | CONFIRM:http://www.securityfocus.com/archive/1/223080 | Christey> The CONFIRM reference by Andre is really this one: | BUGTRAQ:20011026 RWhoisd patched | URL:http://www.securityfocus.com/archive/1/223080 | Christey> CONFIRM:http://lists.research.netsol.com/pipermail/rwhois-announce/2001-October/000022.html | View |
3479 | CVE-2001-0671 | Candidate | Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges. | Proposed (20011122) | ACCEPT(6) Armstrong, Baker, Bishop, Bollinger, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:aix-lpd-bo(7624) | Suggest using following ref in addition to IBM AIXAPAR: | http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01- | 2001.391.1/$file/oar391.txt | View |
Page 194 of 20943, showing 5 records out of 104715 total, starting on record 966, ending on 970