CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3598  CVE-2001-0791  Candidate  Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which do not restrict access.  Proposed (20011012)  MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Foat | REVIEWING(1) Wall  Frech> XF:interscan-viruswall-change-configuration(6641)  View
3600  CVE-2001-0794  Candidate  Buffer overflow in A-FTP Anonymous FTP Server allows remote attackers to cause a denial of service via a long USER command.  Proposed (20011012)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:softhead-aftp-bo(6729)  View
3601  CVE-2001-0795  Candidate  Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.  Proposed (20011012)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:perception-liteserve-reveal-code(6747)  View
3349  CVE-2001-0535  Candidate  Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host"s domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.  Proposed (20011012)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(2) Foat, Frech | NOOP(1) Christey | REVIEWING(1) Wall  Frech> XF:coldfusion-webpublish-execute-code(6790) | XF:coldfusion-email-view-files(6791) | Foat> Includes ColdFusion Server 4.x and earlier | Christey> Consider adding BID:3154  View
3520  CVE-2001-0712  Candidate  The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.  Proposed (20011012)  ACCEPT(2) Baker, Cole | NOOP(1) Armstrong | REJECT(2) Foat, Frech | REVIEWING(1) Wall  Baker> I would argue that a browser executing a script when it shouldn"t is still a vulnerability. If it is supposed to be a non-scriptable file type, and that fails, resulting in a script being executed without the user"s knowledge, then it is a problem, and thus should be included as a vulnerability. I vote this should be accepted, and if Microsoft acknowledges this in their follow up, then you have vendor acknowledgement of the problem as well. | Foat> The candidate does not meet the criteria for a vulnerability or | exposure, even though it describes an unexpected behavior.  View

Page 197 of 20943, showing 5 records out of 104715 total, starting on record 981, ending on 985

Actions