CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3655  CVE-2001-0849  Candidate  viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget.  Modified (20050528)  MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall  Frech> XF:viralator-cgi-command-execution(7440)  View
4431  CVE-2002-0037  Candidate  Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document"s object via a Notes API call (NSFDbReadObject) that directly accesses the object.  Modified (20050528)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat  Christey> Need to find some references for these... probably in | the CERT/CC vulnerability notes. | Frech> XF:lotus-domino-nsfdbreadobject(10095) | http://www.kb.cert.org/vuls/id/657899 | CONFIRM: | http://www-1.ibm.com/support/docview.wss?rs=1&org=sims&doc=CCA46CF459B | A6E4A85256AE3007C92C1 | Christey> Is this the same issue here? | BUGTRAQ:20011217 Lotus Notes: File attachments may be extracted regardless of document security | URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0147.html  View
4697  CVE-2002-0305  Candidate  Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator"s knowledge.  Modified (20050528)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:zot-default-snmp-string(8270)  View
4712  CVE-2002-0320  Candidate  Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field.  Modified (20050528)  ACCEPT(2) Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View
4713  CVE-2002-0321  Candidate  Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.  Modified (20050528)  ACCEPT(2) Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View

Page 20424 of 20943, showing 5 records out of 104715 total, starting on record 102116, ending on 102120

Actions