CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4157 | CVE-2001-1353 | Candidate | ghostscript before 6.51 allows local users to read and write arbitrary files as the "lp" user via the file operator, even with -dSAFER enabled. | Modified (20050702) | ACCEPT(4) Alderson, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | REVIEWING(1) Cox | Christey> [See Mark Cox" email to me 20020617, subject "can-2001-1353"] | Frech> XF:ghostscript-dsafer-read-files(7412) | View |
3647 | CVE-2001-0841 | Candidate | Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie. | Modified (20050702) | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall | Frech> XF:ikonboard-cookie-auth-privileges(7433) | Christey> BID:3486 | URL:http://www.securityfocus.com/bid/3486 | View |
3650 | CVE-2001-0844 | Candidate | Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter. | Modified (20050702) | MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | Frech> XF:bookofguests-cgi-command-execution(7434) | XF:postit-cgi-command-execution(7435) | View |
3736 | CVE-2001-0930 | Candidate | Sendpage.pl allows remote attackers to execute arbitrary commands via a message containing shell metacharacters. | Modified (20050702) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:sendpage-message-command-execution(7609) | View |
3998 | CVE-2001-1194 | Candidate | Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than actual packet size, or (2) fragmented packets whose size exceeds 64 kilobytes after reassembly. | Modified (20050702) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Christey | Christey> This should probably be SPLIT. The 2 vulnerabilities, while | both related to malformed input, are clearly different types | of malformed input. | XF:prestige-dsl-frag-packet-dos(7723) | URL:http://xforce.iss.net/static/7723.php | XF:prestige-dsl-frag-packet-dos(7723) | URL:http://xforce.iss.net/static/7723.php | BID:3711 | URL:http://www.securityfocus.com/bid/3711 | Frech> XF:prestige-dsl-packet-length-dos(7704) | View |
Page 20435 of 20943, showing 5 records out of 104715 total, starting on record 102171, ending on 102175