CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4117  CVE-2001-1313  Candidate  Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  Frech> XF:domino-ldap-protos-format-string(6896)  View
4125  CVE-2001-1321  Candidate  Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  Frech> XF:oracle-ldap-protos-bo(6902)  View
4135  CVE-2001-1331  Candidate  mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mandb-tmpfile-symlink(9989)  View
3375  CVE-2001-0562  Candidate  a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.  Proposed (20010727)  ACCEPT(3) Cole, Frech, Ziese | NOOP(4) Bishop, Christey, Foat, Wall  Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description. | CHANGE> [Bishop changed vote from REVIEWING to NOOP] | Christey> The URL recommended by Andre is *probably* addressing this | problem, but it"s not quite certain. There is insufficient | detail to determine if the vendor has truly acknowledged the | problem. I have an email to a1stats@gadnet.com to see | if I can confirm. | | This is affected by CD:SF-EXEC since multiple executables in the same | package are affected (a1disp.cgi, a1disp2.cgi, a1disp4.cgi, and | a1disp3.cgi). | Christey> Received confirmation via email, 2/26/2002.  View
3511  CVE-2001-0703  Candidate  tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.  Proposed (20010829)  ACCEPT(3) Cole, Frech, Ziese | NOOP(4) Armstrong, Bishop, Foat, Wall    View

Page 19965 of 20943, showing 5 records out of 104715 total, starting on record 99821, ending on 99825

Actions