CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3512  CVE-2001-0704  Candidate  tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.  Proposed (20010829)  ACCEPT(3) Cole, Frech, Ziese | NOOP(4) Armstrong, Bishop, Foat, Wall    View
3513  CVE-2001-0705  Candidate  Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.  Proposed (20010829)  ACCEPT(3) Cole, Frech, Ziese | NOOP(4) Armstrong, Bishop, Foat, Wall    View
3394  CVE-2001-0581  Candidate  Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387.  Modified (20040723)  ACCEPT(3) Cole, Frech, Ziese | NOOP(3) Bishop, Foat, Wall | REVIEWING(1) Christey  CHANGE> [Bishop changed vote from REVIEWING to NOOP] | Christey> A followup claims that if the server runs on Windows 9x, that | Windows 9x can"t handle more than 100 sockets at once, which | may be triggering the bug as opposed to the software. | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3510  CVE-2001-0702  Candidate  Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.  Proposed (20010829)  ACCEPT(3) Cole, Frech, Ziese | NOOP(3) Armstrong, Foat, Wall | REVIEWING(1) Bishop    View
3374  CVE-2001-0561  Candidate  Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a ".." (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.  Modified (20050509)  ACCEPT(3) Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Bishop  Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description.  View

Page 19966 of 20943, showing 5 records out of 104715 total, starting on record 99826, ending on 99830

Actions