CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3660  CVE-2001-0854  Candidate  PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.  Modified (20050703)  MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall  Frech> XF:phpnuke-filemanager-gain-privileges(7478)  View
3659  CVE-2001-0853  Candidate  Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat.  Modified (20050526)  ACCEPT(4) Armstrong, Baker, Bishop, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:getaccess-shellscripts-retrieve-files(7474)  View
3658  CVE-2001-0852  Entry  TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.        View
3657  CVE-2001-0851  Entry  Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.        View
3656  CVE-2001-0850  Entry  A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow.        View

Page 20212 of 20943, showing 5 records out of 104715 total, starting on record 101056, ending on 101060

Actions