CVE List

Id CVE No. Status Description Phase Votes Comments Actions
654  CVE-1999-0673  Candidate  Buffer overflow in ALMail32 POP3 client via From: or To: headers.  Proposed (19991222)  ACCEPT(6) Baker, Blake, Cole, Collins, Levy, Wall | MODIFY(2) Frech, Stracener | NOOP(3) Armstrong, Landfield, Oliver | REVIEWING(1) Ozancin  Stracener> AddRef: ShadowPenguinSecurity:PenguinToolbox,No.037 | Frech> XF:almail-bo | CHANGE> [Cole changed vote from NOOP to ACCEPT]  View
3419  CVE-2001-0606  Candidate  Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.  Modified (20020225-01)  ACCEPT(6) Baker, Bishop, Cole, Wall, Williams, Ziese | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:hp-virtualvault-iws-dos(6110) | CHANGE> [Williams changed vote from REVIEWING to ACCEPT]  View
3445  CVE-2001-0632  Candidate  Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.  Proposed (20010727)  ACCEPT(6) Baker, Bishop, Cole, Prosser, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF: chilisoft-asp-unauthorized-access(6957) | CHANGE> [Williams changed vote from ACCEPT to MODIFY] | Williams> there are actually several issues here, not just the one mentioned in our description. need to modify. | CHANGE> [Williams changed vote from MODIFY to ACCEPT] | Williams> NM my comments. just saw the other CANs. :/ | Prosser> | Vendor Response to issue: | Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities | http://www.securityfocus.com/archive/1/20010224172142.1888.qmail@securityfocus.com  View
3369  CVE-2001-0556  Candidate  The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users" files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.  Proposed (20010727)  ACCEPT(6) Baker, Bishop, Cole, Foat, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> nedit-print-symlink(6424) | Christey> SGI:20011105-01-P | ftp://patches.sgi.com/support/free/security/advisories/20011105-01-P | ADDREF BID:2627 | URL:http://www.securityfocus.com/bid/2627 | (there are different BID"s for the different symlink issues)  View
3368  CVE-2001-0555  Candidate  ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor"s Desktop or (2) the template parameter in SWEditServlet.  Modified (20050509)  ACCEPT(6) Armstrong, Cole, Foat, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> ********************************************************************* | Note that this candidate was inadvertently used in Microsoft bulletin | MS01-044, for an unrelated vulnerability. The ScreamingMedia | SITEware problem is the correct vulnerability for | CVE-2001-0555. A different candidate will be used for the problem | described in the Microsoft bulletin. | ********************************************************************* | Frech> XF:siteware-dot-file-retrieval(6689) | Prosser> http://www01.screamingmedia.com/en/security/sms1001.php | Christey> Consider adding BID:3191 | Christey> CHANGEREF CONFIRM:http://www01.screamingmedia.com/en/security/security_notice.php?doc=sms1001 | CERT-VN:VU#795707 | URL:http://www.kb.cert.org/vuls/id/795707 | BID:2869 | URL:http://www.securityfocus.com/bid/2869 | XF:siteware-dot-file-retrieval(6689) | URL:http://xforce.iss.net/static/6689.php | | *DON"T* add BID:3191 - that"s for the Microsoft issue.  View

Page 19856 of 20943, showing 5 records out of 104715 total, starting on record 99276, ending on 99280

Actions