CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4091  CVE-2001-1287  Candidate  Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:imail-web-calendaring-bo(7279)  View
4093  CVE-2001-1289  Candidate  Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:quake3-arena-connectre-bo(6930)  View
3776  CVE-2001-0971  Candidate  Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.  Modified (20020313-01)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | REJECT(1) Christey  Christey> According to an email message from the vendor | (bcoveney@4d.com) on March 13, 2002, this problem is only | possible if the server admin has already configured the | server"s web root to be at the top-level folder. This is not | the default. As such, any "directory traversal" attack would | not escape above the folder that has already been specified by | the admin. Since this is a generic misconfiguration problem | for all web servers, and not a default configuration of ACI | 4D, then this candidate should not be included in CVE. | | The quote from the vendor is: "By default the 4D WebServer | doesn"t have this behavior. A property has to be turned on to allow | this (despite our warnings of the consequences). We don"t allow pages | outside of our web folder to be served but if the developer of the | site wishes they can set the webroot folder to be whatever they | want. In the system that "krfinisterre@checkfree.com" evaluated the | developer had chosen to set their root folder to be the root of the | computer system (C:) and therefore all the files on the system were | available. By default we set the root folder at the same level as the | database folder so this doesn"t happen. You cannot look at any files | outside the designated WebFolder root tree." | Frech> XF:4d-webserver-directory-traversal(7010)  View
3844  CVE-2001-1040  Candidate  HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> Not jetdirect-jetadmin-telnet-access(6950). | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:jetdirect-admin-password-reset(8713)  View
3771  CVE-2001-0966  Candidate  Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:nudester-sniffer-full-access(7032)  View

Page 20219 of 20943, showing 5 records out of 104715 total, starting on record 101091, ending on 101095

Actions