CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4982  CVE-2002-0591  Candidate  Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall    View
3019  CVE-2001-0198  Candidate  Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.  Modified (20130403)  ACCEPT(1) Frech | NOOP(3) Christey, Lawler, Ziese  Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar"  View
1266  CVE-1999-1286  Candidate  addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.  Modified (20060623)  ACCEPT(1) Frech | NOOP(3) Christey, Cole, Foat  Christey> CHANGE DESC: "via a symlink attack on the printers temporary file." | Add 5.3 as another affected version. | | MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX | SGI:19961203-02-PX may solve this problem, but the advisory is so | vague that it is uncertain whether this was fixed or not. addnetpr is | not specifically named in the advisory, which names netprint, which is | not specified in the original Bugtraq post. In addition, the date on | the advisory is one day earlier than that of the Bugtraq post, though | that could be a difference in time zones. It seems plausible that the | problem had already been patched (the researcher did say "There *was* | [a] race condition") so maybe SGI released this advisory after the | problem was publicized. | | ADDREF BID:330 | URL:http://www.securityfocus.com/bid/330 | | Note: this is a dupe of CVE-1999-1410, but CVE-1999-1410 will | be rejected in favor of CVE-1999-1286.  View
2993  CVE-2001-0172  Candidate  Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.  Proposed (20010309)  ACCEPT(1) Frech | NOOP(2) Lawler, Ziese    View
2994  CVE-2001-0173  Candidate  Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.  Proposed (20010309)  ACCEPT(1) Frech | NOOP(2) Lawler, Ziese    View

Page 20266 of 20943, showing 5 records out of 104715 total, starting on record 101326, ending on 101330

Actions