CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2773 | CVE-2000-1206 | Candidate | Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:apache-virtualhosting-obtain-files(11139) | View |
2774 | CVE-2000-1207 | Candidate | userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844). | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:usermode-userhelper-bypass-security(11089) | View |
2775 | CVE-2000-1208 | Candidate | Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Frech, Green | NOOP(2) Foat, Wall | View | |
5051 | CVE-2002-0661 | Candidate | Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing (backslash) characters. | Modified (20050610) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Christey> BID:5434 | URL:http://www.securityfocus.com/bid/5434 | Frech> XF:apache-encoded-directory-traversal(9808) | View |
5092 | CVE-2002-0702 | Candidate | Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS server response. | Proposed (20020726) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Foat, Wall | View |
Page 19865 of 20943, showing 5 records out of 104715 total, starting on record 99321, ending on 99325