CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3566  CVE-2001-0759  Candidate  Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file or directory with a long pathname, which is processed during an unmount.  Proposed (20011012)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:bestcrypt-bctool-bo(6690)  View
3568  CVE-2001-0761  Candidate  Buffer overflow in HttpSave.dll in Trend Micro InterScan WebManager 1.2 allows remote attackers to execute arbitrary code via a long value to a certain parameter.  Proposed (20011012)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | REVIEWING(1) Christey  Christey> CD:SF-LOC may suggest merging with CVE-2001-0678 | Frech> XF:interscan-webmanager-httpsave-bo(6788) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> There is evidence that this problem was confirmed by Trend, | but there are some inconsistencies. | MISC:http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionID=9682 | Note, however, that the date of the patch description at | MISC:http://solutionfile.trendmicro.com/SolutionFile/9682/en/ReadMe-BufferOverflowPatch.txt | is June 19th, but the Bugtraq post was July 2, and the poster | said that a patch had not been available yet. However, the | poster also said that they had notified Trend on June 11. | Add that the Action parameter is the one with the overflow. | | This patch description only identifies HttpSave.dll, not | RegGo.dll (as identified by CVE-2001-0678), but it implies | that multiple DLL"s may have been fixed. Looking at the DLL"s | in the patch, there is RegGo.dll and a number of other DLL"s. | However, this RegGo.dll is different than the one from | the patch for CVE-2001-0678, so maybe they fixed yet another | problem here. | | That problem might be: | BUGTRAQ:20010621 TrendMicro InterScan WebManager Version 1.2 RegGo.dll Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/192645 | where the discloser said that the problem was discovered | in June 6 and implied that Trend Micro would fix the problem, | so Trend was notified sometime between June 6 and June 21. | So, the dates might imply that Trend fixed both the | HTTPSave.dll and this variant (if in fact it"s a variant and | not a rediscovery of CVE-2001-0678) in a single patch. | If true, then that would argue that this candidate should be | merged with the RegGo.dll variant reported in the above | Bugtraq reference, along with some of the other DLL"s - just | in case someone rediscovers THOSE, too. | | Other DLL"s in this patch are covered in other posts | in the same time frame by the same person. | HttpSaveCVP.dll and HttpSaveCSP.dll are in: | BUGTRAQ:20010628 [SNS Advisory No.35] TrendMicro InterScan VirusWall 3.51 HttpSaveC*P.dll Buffer Overflow | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0388.html | smtpscan.dll is described in: | BUGTRAQ:20010628 [SNS Advisory No.34] TrendMicro InterScan VirusWall 3.51 smtpscan.dll Buffer Overflow | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0387.html  View
3569  CVE-2001-0762  Candidate  Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument.  Proposed (20011012)  MODIFY(2) Christey, Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:suid-wrapper-argument-bo(6675) | Christey> Add "suid wrapper" to desc. | ADDREF BID:2837 | URL:http://www.securityfocus.com/bid/2837  View
3573  CVE-2001-0766  Candidate  Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache"s filters.  Proposed (20011012)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Frech> XF:macos-apache-file-disclosure(6687) | Christey> CERT-VN:VU#439395 | URL:http://www.kb.cert.org/vuls/id/439395  View
3574  CVE-2001-0767  Candidate  Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.  Proposed (20011012)  ACCEPT(3) Armstrong, Cole, Foat | NOOP(2) Christey, Wall | REJECT(1) Frech  Frech> DUPE CVE-2000-0640 | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002  View

Page 200 of 20943, showing 5 records out of 104715 total, starting on record 996, ending on 1000

Actions