CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3830  CVE-2001-1026  Candidate  Trend Micro InterScan AppletTrap 2.0 does not properly filter URLs when they are modified in certain ways such as (1) using a double slash (//) instead of a single slash, (2) URL-encoded characters, (3) requesting the IP address instead of the domain name, or (4) using a leading 0 in an octet of an IP address.  Modified (20050706)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Christey, Foat, Wall | REVIEWING(1) Green  Christey> Consider adding BID:2996 | Christey> Consider adding BID:2998 | Christey> Consider adding BID:2999 | Christey> Consider adding BID:3000 | Christey> fix typo: "leading a leading"  View
3178  CVE-2001-0358  Candidate  Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View
3179  CVE-2001-0359  Candidate  Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View
3180  CVE-2001-0360  Candidate  Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View
3233  CVE-2001-0415  Candidate  REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View

Page 20114 of 20943, showing 5 records out of 104715 total, starting on record 100566, ending on 100570

Actions