CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3848  CVE-2001-1044  Candidate  Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View
3849  CVE-2001-1045  Candidate  Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View
3861  CVE-2001-1057  Candidate  The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View
3862  CVE-2001-1058  Candidate  The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View
3874  CVE-2001-1070  Candidate  Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View

Page 20083 of 20943, showing 5 records out of 104715 total, starting on record 100411, ending on 100415

Actions