CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1031  CVE-1999-1051  Candidate  Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Frech> XF:formhandler-cgi-reply-message(7782) | Christey> I view one of these as a configuration issue: FormHandler.cgi | *could* be configured to limit hard-coded pathnames to a single | directory which, while being an information leak, would still be | "reasonably secure." But by default, it"s just not configured that | way. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View
1287  CVE-1999-1307  Candidate  Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.  Proposed (20010912)  ACCEPT(4) Armstrong, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF;novell-unixware-urestore-root(7211)  View
1543  CVE-1999-1563  Candidate  Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:icmp-redirect(285)  View
1032  CVE-1999-1052  Candidate  Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.  Proposed (20010912)  ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(2) Cole, Foat  Frech> XF:frontpage-formresults-world-readable(8362)  View
1544  CVE-1999-1564  Candidate  FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.  Proposed (20010912)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:freebsd-nfs-access-dos(8325)  View

Page 204 of 20943, showing 5 records out of 104715 total, starting on record 1016, ending on 1020

Actions