CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3660 | CVE-2001-0854 | Candidate | PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user. | Modified (20050703) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:phpnuke-filemanager-gain-privileges(7478) | View |
3659 | CVE-2001-0853 | Candidate | Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat. | Modified (20050526) | ACCEPT(4) Armstrong, Baker, Bishop, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:getaccess-shellscripts-retrieve-files(7474) | View |
3658 | CVE-2001-0852 | Entry | TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header. | View | |||
3657 | CVE-2001-0851 | Entry | Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. | View | |||
3656 | CVE-2001-0850 | Entry | A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow. | View |
Page 20212 of 20943, showing 5 records out of 104715 total, starting on record 101056, ending on 101060