CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3573 | CVE-2001-0766 | Candidate | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache"s filters. | Proposed (20011012) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:macos-apache-file-disclosure(6687) | Christey> CERT-VN:VU#439395 | URL:http://www.kb.cert.org/vuls/id/439395 | View |
5363 | CVE-2002-0975 | Candidate | Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. | Modified (20071101) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall | Christey> ADDREF MS:MS02-066 - "the patch sets the Kill Bit on a legacy | DirectX ActiveX control which has been retired but which has a | security vulnerability." | ADDREF MSKB:Q810202 - deals with "a security vulnerability | that exists in the DirectX Files Viewer control (Xweb.ocx)" | | Thanks to Andrew G. Tereschenko (the researcher) for this | additional information. | Frech> XF:ms-directx-files-viewer-bo(9877) | Christey> fix typo: "execute arbitrary [CODE]" | View |
2404 | CVE-2000-0835 | Candidate | search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter. | Modified (20100115) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Collins, Wall | REJECT(2) Baker, Magdych | Magdych> Unless the beta product is in very widespread use, or the product is in | "perpetual beta" (e.g. ICQ), I would prefer not to include beta software. | Christey> XF:sambar-search-view-folder | Frech> XF:sambar-search-view-folder(5247) | Baker> Unless we change our CD:EX-BETA, we should reject this entry. Perhaps we need to address the issue of Beta software again, but the previous discussion was pretty thorough and I believe the editorial board was unanimous in excluding normal beta software. | Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar" | View |
3632 | CVE-2001-0826 | Candidate | Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD. | Proposed (20011122) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:cesarftp-long-command-bo(6768) | View |
3645 | CVE-2001-0839 | Candidate | ibillpm.pl in iBill password management system generates weak passwords based on a client"s MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing. | Modified (20050528) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:ibillpm-cgi-insecure-password(7352) | View |
Page 19797 of 20943, showing 5 records out of 104715 total, starting on record 98981, ending on 98985