CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3573  CVE-2001-0766  Candidate  Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache"s filters.  Proposed (20011012)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Frech> XF:macos-apache-file-disclosure(6687) | Christey> CERT-VN:VU#439395 | URL:http://www.kb.cert.org/vuls/id/439395  View
5363  CVE-2002-0975  Candidate  Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.  Modified (20071101)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> ADDREF MS:MS02-066 - "the patch sets the Kill Bit on a legacy | DirectX ActiveX control which has been retired but which has a | security vulnerability." | ADDREF MSKB:Q810202 - deals with "a security vulnerability | that exists in the DirectX Files Viewer control (Xweb.ocx)" | | Thanks to Andrew G. Tereschenko (the researcher) for this | additional information. | Frech> XF:ms-directx-files-viewer-bo(9877) | Christey> fix typo: "execute arbitrary [CODE]"  View
2404  CVE-2000-0835  Candidate  search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.  Modified (20100115)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Collins, Wall | REJECT(2) Baker, Magdych  Magdych> Unless the beta product is in very widespread use, or the product is in | "perpetual beta" (e.g. ICQ), I would prefer not to include beta software. | Christey> XF:sambar-search-view-folder | Frech> XF:sambar-search-view-folder(5247) | Baker> Unless we change our CD:EX-BETA, we should reject this entry. Perhaps we need to address the issue of Beta software again, but the previous discussion was pretty thorough and I believe the editorial board was unanimous in excluding normal beta software. | Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar"  View
3632  CVE-2001-0826  Candidate  Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.  Proposed (20011122)  MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall  Frech> XF:cesarftp-long-command-bo(6768)  View
3645  CVE-2001-0839  Candidate  ibillpm.pl in iBill password management system generates weak passwords based on a client"s MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.  Modified (20050528)  MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall  Frech> XF:ibillpm-cgi-insecure-password(7352)  View

Page 19797 of 20943, showing 5 records out of 104715 total, starting on record 98981, ending on 98985

Actions