CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2908  CVE-2001-0087  Candidate  itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2918  CVE-2001-0097  Candidate  The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> Version is listed as 3.61 (see | http://support.infinite.com/kb/648.asp) | Also, vendor seems to have issued a verification (see above | document): | - - WebMail: Fix for an exception error triggered by a POST request | with | an extremely long garbage URL. (v3.61.08)  View
2919  CVE-2001-0098  Candidate  Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2924  CVE-2001-0103  Candidate  CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.  Modified (20071018)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2925  CVE-2001-0104  Candidate  MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View

Page 20253 of 20943, showing 5 records out of 104715 total, starting on record 101261, ending on 101265

Actions