CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3537 | CVE-2001-0729 | Candidate | Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters. | Modified (20071115) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately. | View |
3554 | CVE-2001-0747 | Candidate | Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request. | Proposed (20011012) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:netscape-enterprise-uri-bo(6554) | Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE. | View |
3731 | CVE-2001-0925 | Candidate | The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Green | NOOP(2) Christey, Wall | REJECT(1) Frech | Frech> I"m using both candidates until we decide if it is a dupe, | and then which | candidate to deprecate. | Christey> BUGTRAQ:20010615 TSLSA-2001-0010 - Apache | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0180.html | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately. | View |
3541 | CVE-2001-0734 | Candidate | Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine. | Proposed (20011012) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Frech | NOOP(1) Wall | View | |
821 | CVE-1999-0841 | Candidate | Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type. | Modified (20071022) | ACCEPT(5) Armstrong, Baker, Cole, Dik, Stracener | MODIFY(1) Frech | REVIEWING(1) Prosser | Frech> XF:cde-mailtool-bo | Dik> bug 4163471 | (Root access is only possible when mail is send to root and he | uses dtmail to read it) | View |
Page 19887 of 20943, showing 5 records out of 104715 total, starting on record 99431, ending on 99435