CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3338  CVE-2001-0524  Candidate  eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.  Proposed (20010727)  ACCEPT(4) Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall    View
3395  CVE-2001-0582  Candidate  Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a ".." (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.  Modified (20050510)  ACCEPT(4) Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall    View
1720  CVE-2000-0142  Candidate  The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.  Proposed (20000216)  ACCEPT(4) Bishop, Blake, Cole, LeBlanc | MODIFY(2) Frech, Levy | NOOP(2) Baker, Christey  Frech> XF:timbuktu-auth-dos | Levy> BID 984 | Christey> BUGTRAQ:20000412 Timbuktu DoS repaired by Netopia | http://www.securityfocus.com/archive/1/54850 | BID:984  View
4504  CVE-2002-0110  Candidate  Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file.  Modified (20050328)  ACCEPT(4) Balinsky, Cole, Frech, Green | NOOP(2) Foat, Wall    View
4538  CVE-2002-0144  Candidate  Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a .. (dot dot) attack.  Proposed (20020315)  ACCEPT(4) Balinsky, Cole, Frech, Green | NOOP(2) Foat, Wall    View

Page 19907 of 20943, showing 5 records out of 104715 total, starting on record 99531, ending on 99535

Actions