CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3929  CVE-2001-1125  Candidate  Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.  Proposed (20020315)  ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall  Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split  View
3930  CVE-2001-1126  Candidate  Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.  Proposed (20020315)  ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall  Green> IN ONE VERSION, BUT NOT IN THE OTHER | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Concur with Analysis, this should be split. The DoS would | include all versions of LiveUpdate, 1.4.x through 1.6.x. The | potential for unauthorized code execution only impacts 1.4.x through | 1.5.x.  View
3924  CVE-2001-1120  Candidate  Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.  Modified (20040811)  ACCEPT(7) Armstrong, Baker, Cole, Foat, Frech, Green, Ziese | NOOP(1) Christey | REVIEWING(1) Wall  Green> Acknowledged by vendor in Macromedia Product Security Bulletin (MPSB01-07) issued in July, 2001 | Foat> Note that the link to the confirm should be | http://www.macomedia.com/v1/handlers/index.cfm?id=21566. | Christey> Add period to the end of the description.  View
4187  CVE-2001-1384  Candidate  ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp.  Proposed (20020830)  ACCEPT(7) Armstrong, Baker, Cole, Cox, Frech, Green, Wall | NOOP(1) Foat    View
2772  CVE-2000-1205  Candidate  Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.  Modified (20070926)  ACCEPT(7) Armstrong, Baker, Cole, Cox, Foat, Green, Wall | MODIFY(1) Frech  Frech> XF:apache-printenv-xss(10938)  View

Page 19852 of 20943, showing 5 records out of 104715 total, starting on record 99256, ending on 99260

Actions