CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6930  CVE-2003-0101  Candidate  miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.  Modified (20080207)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SGI:20030602-01-I | The "websetup v 3.5 package from IRIX 6.5.20 Applications CD" | uses Webmin; may wish to add this name to the description. | Christey> DEBIAN:DSA-319 | Christey> CIAC:N-058 | URL:http://www.ciac.org/ciac/bulletins/n-058.shtml | ENGARDE:ESA-20030225-006 | URL:http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0008.html | HP:HPSBUX0303-250 | URL:http://archives.neohapsis.com/archives/hp/2003-q1/0063.html | BID:6915 | URL:http://www.securityfocus.com/bid/6915  View
6929  CVE-2003-0100  Entry  Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.        View
6928  CVE-2003-0099  Candidate  Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.  Modified (20071016)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SUSE:SuSE-SA:2003:022 | CALDERA:CSSA-2003-015.0 | Christey> DEBIAN:DSA-277 | URL:http://www.debian.org/security/2003/dsa-277 | Christey> As observed in an email to us by a third party, it appears | that 3.8.6 is probably not affected by this, so the | description should be changed to refer to "3.10.x before | 3.10.5, and 3.8.x before 3.8.6". | Christey> An email from Kern Sibbald on August 21, 2003, confirmed that | 3.8.6 and 3.10.5 fixed the issue. | | CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=137892  View
6927  CVE-2003-0098  Candidate  Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.  Modified (20071016)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> SUSE:SuSE-SA:2003:022 | CALDERA:CSSA-2003-015.0 | Christey> DEBIAN:DSA-277 | URL:http://www.debian.org/security/2003/dsa-277 | Christey> CHANGEREF BID:6828 | (BID:7200 is for the overflows)  View
6926  CVE-2003-0097  Entry  Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).        View

Page 19558 of 20943, showing 5 records out of 104715 total, starting on record 97786, ending on 97790

Actions