CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4499 | CVE-2002-0105 | Candidate | CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey | Christey> CALDERA:CSSA-2002-SCO.18 | XF:cde-dt-world-writable(9045) | URL:http://www.iss.net/security_center/static/9045.php | Note: the advisory sort-of implies that world-write | permissions were the key problem, so the fact that a symlink | attack could take place did not necessarily mean that a | symlink following vulnerability really existed, in the sense | that symlink attacks don"t exist in directories that are | not writable by other users (well, without those users | exploiting some *other* vulnerability to allow them to create | the symlink!) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Hmmm... should XF:cde-dt-world-writable(9045) really be added | here? ISS may have "split" between the permissions issue | and the symlink problem. | View |
4013 | CVE-2001-1209 | Candidate | Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey | Christey> INCLUSION: The author of the zml.cgi program says that the vulnerable | version is not his, and that zml.cgi does not take a file parameter. | If this is an adaptation of that zml.cgi program, and the adaptation | is not generally available, then it should not be included in CVE. | Almost all of the hits on Google for "zml.cgi" are references to the | reported vulnerability, and a search for "zml" doesn"t turn up any | obvious web pages, so it cannot be determined if there is another | product that happens to use a script named zml.cgi. | View |
4494 | CVE-2002-0100 | Candidate | AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file. | Modified (20050710) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View | |
4498 | CVE-2002-0104 | Candidate | AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View | |
4500 | CVE-2002-0106 | Candidate | BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View |
Page 20072 of 20943, showing 5 records out of 104715 total, starting on record 100356, ending on 100360