CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3655 | CVE-2001-0849 | Candidate | viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget. | Modified (20050528) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:viralator-cgi-command-execution(7440) | View |
4431 | CVE-2002-0037 | Candidate | Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document"s object via a Notes API call (NSFDbReadObject) that directly accesses the object. | Modified (20050528) | ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat | Christey> Need to find some references for these... probably in | the CERT/CC vulnerability notes. | Frech> XF:lotus-domino-nsfdbreadobject(10095) | http://www.kb.cert.org/vuls/id/657899 | CONFIRM: | http://www-1.ibm.com/support/docview.wss?rs=1&org=sims&doc=CCA46CF459B | A6E4A85256AE3007C92C1 | Christey> Is this the same issue here? | BUGTRAQ:20011217 Lotus Notes: File attachments may be extracted regardless of document security | URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0147.html | View |
4697 | CVE-2002-0305 | Candidate | Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator"s knowledge. | Modified (20050528) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:zot-default-snmp-string(8270) | View |
4712 | CVE-2002-0320 | Candidate | Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field. | Modified (20050528) | ACCEPT(2) Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall | View | |
4713 | CVE-2002-0321 | Candidate | Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks. | Modified (20050528) | ACCEPT(2) Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall | View |
Page 20424 of 20943, showing 5 records out of 104715 total, starting on record 102116, ending on 102120