CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3537  CVE-2001-0729  Candidate  Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.  Modified (20071115)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View
3554  CVE-2001-0747  Candidate  Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request.  Proposed (20011012)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:netscape-enterprise-uri-bo(6554) | Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE.  View
3731  CVE-2001-0925  Candidate  The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Green | NOOP(2) Christey, Wall | REJECT(1) Frech  Frech> I"m using both candidates until we decide if it is a dupe, | and then which | candidate to deprecate. | Christey> BUGTRAQ:20010615 TSLSA-2001-0010 - Apache | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0180.html | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View
3541  CVE-2001-0734  Candidate  Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.  Proposed (20011012)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Frech | NOOP(1) Wall    View
821  CVE-1999-0841  Candidate  Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.  Modified (20071022)  ACCEPT(5) Armstrong, Baker, Cole, Dik, Stracener | MODIFY(1) Frech | REVIEWING(1) Prosser  Frech> XF:cde-mailtool-bo | Dik> bug 4163471 | (Root access is only possible when mail is send to root and he | uses dtmail to read it)  View

Page 19887 of 20943, showing 5 records out of 104715 total, starting on record 99431, ending on 99435

Actions