CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3623  CVE-2001-0817  Candidate  Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.  Modified (20020226-01)  ACCEPT(6) Armstrong, Baker, Bishop, Cole, Foat, Frech | NOOP(2) Christey, Wall  Christey> CERT:CA-2001-32 | URL:http://www.cert.org/advisories/CA-2001-32.html | CERT-VN:VU#638011 | URL:http://www.kb.cert.org/vuls/id/638011 | Christey> BID:3561 | URL:http://www.securityfocus.com/bid/3561 | CIAC:M-021 | http://www.ciac.org/ciac/bulletins/m-021.shtml  View
3641  CVE-2001-0835  Candidate  Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.  Modified (20020226-01)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Frech> XF:webalizer-html-tag-host(7350) | XF:webalizer-html-tags-keywords(7351) | Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat) | Christey> CONECTIVA:CLA-2001:435 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435  View
3651  CVE-2001-0845  Candidate  Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.  Modified (20020226-01)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:openvms-dms-unauthorized-access(7425)  View
3653  CVE-2001-0847  Candidate  Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.  Modified (20020226-01)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Bishop, Foat, Wall  Frech> XF:lotus-domino-navigator-access(7423)  View
950  CVE-1999-0970  Candidate  The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.  Modified (20020226-01)  ACCEPT(3) Baker, Blake, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy  Frech> XF:omnihttpd-dos | Christey> Some sort of confirmation might be findable at: | http://www.omnicron.ab.ca/httpd/docs/release.html | Christey> See http://www.omnicron.ab.ca/index.html | The August 16, 2000 news item says "This release fixes some | security problems." It"s for version 2.07, but the discloser | didn"t say what version was available. | | Other security fixes are in the release notes at | http://www.omnicron.ab.ca/httpd/docs/release.html Notes for | Professional Version 1.01 say "Patched up two security weaknesses." | Notes for version 2.07 say "Fixes dot-appending vulnerability." | Professional Alpha 7 says "Revamped CGI launching and security," | Professional Alpha 4 says "Fixed SSI path mapping and security | problems," Alpha 5 says "Security fixup." | | In other words, you can"t tell whether they"ve fixed this bug | or not. | Christey> BID:1808 | URL:http://www.securityfocus.com/bid/1808  View

Page 20393 of 20943, showing 5 records out of 104715 total, starting on record 101961, ending on 101965

Actions