CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3551  CVE-2001-0744  Candidate  Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.  Proposed (20011012)  ACCEPT(4) Armstrong, Baker, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:horde-popen-remote-access(5244) | Christey> Need to examine the codebase relationship between Horde and | IMP. | Christey> BID:3066 | URL:http://online.securityfocus.com/bid/3066  View
3553  CVE-2001-0746  Candidate  Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.  Proposed (20011012)  ACCEPT(6) Armstrong, Baker, Cole, Foat, Frech, Wall | NOOP(1) Christey  Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE.  View
3554  CVE-2001-0747  Candidate  Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request.  Proposed (20011012)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:netscape-enterprise-uri-bo(6554) | Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE.  View
3563  CVE-2001-0756  Candidate  CatalogMgr.pl in VirtualCatalog (incorrectly claimed to be in VirtualCart) allows remote attackers to execute arbitrary code via the template parameter.  Proposed (20011012)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:virtualcatalog-command-execution(6663)  View
3565  CVE-2001-0758  Candidate  Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command.  Proposed (20011012)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Frech> XF:shambala-ftp-cwd-directory-traversal(7418) | Christey> Other .. problems were found in 4.5 as described in: | BUGTRAQ:20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0282.html | CD:SF-LOC might suggest merging these two. (I"m working | on creating a CAN for the newer discovery).  View

Page 199 of 20943, showing 5 records out of 104715 total, starting on record 991, ending on 995

Actions