CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4045  CVE-2001-1241  Candidate  Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4046  CVE-2001-1242  Candidate  Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4048  CVE-2001-1244  Candidate  Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4049  CVE-2001-1245  Candidate  Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall  CHANGE> [Green changed vote from REVIEWING to ACCEPT]  View
4060  CVE-2001-1256  Candidate  kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.  Modified (20090302)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View

Page 19972 of 20943, showing 5 records out of 104715 total, starting on record 99856, ending on 99860

Actions