CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2908 | CVE-2001-0087 | Candidate | itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2918 | CVE-2001-0097 | Candidate | The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> Version is listed as 3.61 (see | http://support.infinite.com/kb/648.asp) | Also, vendor seems to have issued a verification (see above | document): | - - WebMail: Fix for an exception error triggered by a POST request | with | an extremely long garbage URL. (v3.61.08) | View |
2919 | CVE-2001-0098 | Candidate | Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2924 | CVE-2001-0103 | Candidate | CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords. | Modified (20071018) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2925 | CVE-2001-0104 | Candidate | MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View |
Page 20253 of 20943, showing 5 records out of 104715 total, starting on record 101261, ending on 101265