CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3551 | CVE-2001-0744 | Candidate | Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file. | Proposed (20011012) | ACCEPT(4) Armstrong, Baker, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:horde-popen-remote-access(5244) | Christey> Need to examine the codebase relationship between Horde and | IMP. | Christey> BID:3066 | URL:http://online.securityfocus.com/bid/3066 | View |
3553 | CVE-2001-0746 | Candidate | Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods. | Proposed (20011012) | ACCEPT(6) Armstrong, Baker, Cole, Foat, Frech, Wall | NOOP(1) Christey | Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE. | View |
3554 | CVE-2001-0747 | Candidate | Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request. | Proposed (20011012) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:netscape-enterprise-uri-bo(6554) | Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE. | View |
3563 | CVE-2001-0756 | Candidate | CatalogMgr.pl in VirtualCatalog (incorrectly claimed to be in VirtualCart) allows remote attackers to execute arbitrary code via the template parameter. | Proposed (20011012) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:virtualcatalog-command-execution(6663) | View |
3565 | CVE-2001-0758 | Candidate | Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command. | Proposed (20011012) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:shambala-ftp-cwd-directory-traversal(7418) | Christey> Other .. problems were found in 4.5 as described in: | BUGTRAQ:20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0282.html | CD:SF-LOC might suggest merging these two. (I"m working | on creating a CAN for the newer discovery). | View |
Page 199 of 20943, showing 5 records out of 104715 total, starting on record 991, ending on 995