CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3123  CVE-2001-0302  Candidate  Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.  Proposed (20010404)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:pi3web-isapi-bo(6113) | Christey> CONFIRM:http://sourceforge.net/tracker/index.php?func=detail&aid=410354&group_id=17753&atid=117753  View
3229  CVE-2001-0411  Candidate  Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REJECT(1) Meunier  Frech> XF:reliant-unix-ppd-symlink(6408) | Frech> Change to reliant-unix-icmp-dos(6646) | Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> lower level (more precise) duplicate or sub-class of high | level description CVE-1999-0214  View
3198  CVE-2001-0380  Candidate  Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string "ILMI".  Modified (20090302)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:cisco-ios-modify-snmp(6169) | Christey> Fix the date of the Bugtraq post | Christey> The Bugtraq poster didn"t provide many details, but said that | the vendor was out of business. It"s possible that this ILMI | community string has no relationship with the Cisco ILMI | problem, in which case this should remain a separate CAN. | Christey> Further research suggests that ILMI is a standard | specification for ATM, and therefore this CAN should remain split from | the Cisco ILMI problem (CVE-2001-0711).  View
3238  CVE-2001-0420  Candidate  Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547  View
3264  CVE-2001-0447  Candidate  Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:software602-lan-suite-bo(5583) | Possible duplicate or close similarity with | BID-1979/CVE-2000-1115. | Christey> The BID doesn"t look quite like this; I think it"s for | CVE-2001-0448  View

Page 19804 of 20943, showing 5 records out of 104715 total, starting on record 99016, ending on 99020

Actions