CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3623 | CVE-2001-0817 | Candidate | Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request. | Modified (20020226-01) | ACCEPT(6) Armstrong, Baker, Bishop, Cole, Foat, Frech | NOOP(2) Christey, Wall | Christey> CERT:CA-2001-32 | URL:http://www.cert.org/advisories/CA-2001-32.html | CERT-VN:VU#638011 | URL:http://www.kb.cert.org/vuls/id/638011 | Christey> BID:3561 | URL:http://www.securityfocus.com/bid/3561 | CIAC:M-021 | http://www.ciac.org/ciac/bulletins/m-021.shtml | View |
3641 | CVE-2001-0835 | Candidate | Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup. | Modified (20020226-01) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:webalizer-html-tag-host(7350) | XF:webalizer-html-tags-keywords(7351) | Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat) | Christey> CONECTIVA:CLA-2001:435 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435 | View |
3651 | CVE-2001-0845 | Candidate | Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources. | Modified (20020226-01) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:openvms-dms-unauthorized-access(7425) | View |
3653 | CVE-2001-0847 | Candidate | Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID. | Modified (20020226-01) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Bishop, Foat, Wall | Frech> XF:lotus-domino-navigator-access(7423) | View |
950 | CVE-1999-0970 | Candidate | The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created. | Modified (20020226-01) | ACCEPT(3) Baker, Blake, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy | Frech> XF:omnihttpd-dos | Christey> Some sort of confirmation might be findable at: | http://www.omnicron.ab.ca/httpd/docs/release.html | Christey> See http://www.omnicron.ab.ca/index.html | The August 16, 2000 news item says "This release fixes some | security problems." It"s for version 2.07, but the discloser | didn"t say what version was available. | | Other security fixes are in the release notes at | http://www.omnicron.ab.ca/httpd/docs/release.html Notes for | Professional Version 1.01 say "Patched up two security weaknesses." | Notes for version 2.07 say "Fixes dot-appending vulnerability." | Professional Alpha 7 says "Revamped CGI launching and security," | Professional Alpha 4 says "Fixed SSI path mapping and security | problems," Alpha 5 says "Security fixup." | | In other words, you can"t tell whether they"ve fixed this bug | or not. | Christey> BID:1808 | URL:http://www.securityfocus.com/bid/1808 | View |
Page 20393 of 20943, showing 5 records out of 104715 total, starting on record 101961, ending on 101965