CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3071  CVE-2001-0250  Candidate  The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.  Proposed (20010404)  ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(2) Wall, Ziese  Bishop> This is a problem if the policy says it is. It may not be a security | problem in general, though. I voted accept because it may be a problem.  View
3083  CVE-2001-0262  Candidate  Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.  Proposed (20010524)  ACCEPT(3) Baker, Cole, Williams | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese  Frech> XF:netscape-smartdownload-sdph20-bo(6403) | Christey> BUGTRAQ:20010418 Netscape SmartDownload 1.3 Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/177589 | Add sdph20.dll as affected component in description, as | indicated by above post. | Christey> Consider adding BID:2615  View
3085  CVE-2001-0264  Candidate  Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.  Proposed (20010524)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Oliver, Wall | REVIEWING(1) Ziese  Frech> XF:bpftp-obtain-credentials(6330)  View
3153  CVE-2001-0332  Candidate  Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.  Proposed (20010524)  ACCEPT(4) Baker, Cole, Wall, Ziese | MODIFY(1) Frech | NOOP(1) Renaud | RECAST(1) Williams | REJECT(1) Magdych | REVIEWING(1) Christey  Magdych> Duplicate of CVE-0246 | Christey> While it may look like CVE-2001-0332 is a duplicate of | CVE-2001-0246, Microsoft specifically identifies two separate | variants of the same problem in its advisory, namely 0332 and | 0246. However, CD:SF-LOC currently suggests merging problems | of the same type that appear and are fixed in the same | software versions, and thus these 2 candidates *might* | in fact be duplicates - relative to CD:SF-LOC. Microsoft | needs to be consulted on this. | Williams> merge with CVE-0246 | Frech> XF:ie-frame-verification-read-files(6086) | XF:ie-frame-verification-variant(6748) | CVE-2001-0092 is also assigned to the | ie-frame-verification-files(6086), but shouldn"t be considered a | duplicate.  View
3158  CVE-2001-0337  Candidate  The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.  Proposed (20010524)  ACCEPT(6) Baker, Cole, Renaud, Wall, Williams, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:iis-webdav-lock-dos(6549) | Christey> ADDREF? BID:2736 | URL:http://www.securityfocus.com/bid/2736 | ADDREF? BUGTRAQ:20010517 def-2001-26: IIS WebDav Lock Method Memory Leak DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0170.html | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View

Page 20646 of 20943, showing 5 records out of 104715 total, starting on record 103226, ending on 103230

Actions