CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4128  CVE-2001-1324  Candidate  cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.  Modified (20050526)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:idtools-cmvlogin-root-privileges(9987)  View
4678  CVE-2002-0286  Candidate  The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.  Modified (20050526)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:sitenews-getpassword-add-users(8181) | CONFIRM:http://www.securitytracker.com/alerts/2002/Feb/100349 | 8.html  View
3659  CVE-2001-0853  Candidate  Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat.  Modified (20050526)  ACCEPT(4) Armstrong, Baker, Bishop, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:getaccess-shellscripts-retrieve-files(7474)  View
4001  CVE-2001-1197  Candidate  klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file.  Modified (20050526)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese  Frech> XF:kdeutils-klprfax-symlink(7700)  View
4926  CVE-2002-0535  Candidate  Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.  Modified (20050527)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> ADDREF BID:4561 | URL:http://www.securityfocus.com/bid/4561  View

Page 20421 of 20943, showing 5 records out of 104715 total, starting on record 102101, ending on 102105

Actions