CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3830  CVE-2001-1026  Candidate  Trend Micro InterScan AppletTrap 2.0 does not properly filter URLs when they are modified in certain ways such as (1) using a double slash (//) instead of a single slash, (2) URL-encoded characters, (3) requesting the IP address instead of the domain name, or (4) using a leading 0 in an octet of an IP address.  Modified (20050706)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Christey, Foat, Wall | REVIEWING(1) Green  Christey> Consider adding BID:2996 | Christey> Consider adding BID:2998 | Christey> Consider adding BID:2999 | Christey> Consider adding BID:3000 | Christey> fix typo: "leading a leading"  View
8724  CVE-2004-0296  Candidate  TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.  Modified (20050707)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> The description is incomplete. Wonder what it was about the | original researcher that was important enough to note? | Christey> What was I saying in the desc about the original researcher???  View
4395  CVE-2002-0001  Candidate  Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the address list.  Modified (20050707)  ACCEPT(4) Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Christey> I need to review this for accuracy; is it just a buffer | overflow? See Mark Cox" comments in his "Chinese Whisper" | article. | Frech> XF:mutt-address-handling-bo(7759) | Christey> See Caldera advisory for a good, short description of the | issue. | BID:3774 | URL:http://www.securityfocus.com/bid/3774 | SUSE:SuSE-SA:2002:001 | URL:http://www.suse.de/de/support/security/2002_001_mutt_txt.html | CONECTIVA:CLA-2002:449 | DEBIAN:DSA-096 | FREEBSD:FreeBSD-SA-02:04 | HP:HPSBTL0201-011 | URL:http://online.securityfocus.com/advisories/3778 | CALDERA:CSSA-2002-002.0 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2002-002.0.txt  View
4656  CVE-2002-0264  Candidate  PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.  Modified (20050707)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:powerftp-ftpserver-ini-plaintext(8183)  View
4660  CVE-2002-0268  Candidate  Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.  Modified (20050707)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:biologon3-gina-bypass-authentication(8201) | CONFIRM:http://www.identix.com/support/sp_it.html  View

Page 20443 of 20943, showing 5 records out of 104715 total, starting on record 102211, ending on 102215

Actions