CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3071 | CVE-2001-0250 | Candidate | The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command. | Proposed (20010404) | ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(2) Wall, Ziese | Bishop> This is a problem if the policy says it is. It may not be a security | problem in general, though. I voted accept because it may be a problem. | View |
3083 | CVE-2001-0262 | Candidate | Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL. | Proposed (20010524) | ACCEPT(3) Baker, Cole, Williams | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese | Frech> XF:netscape-smartdownload-sdph20-bo(6403) | Christey> BUGTRAQ:20010418 Netscape SmartDownload 1.3 Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/177589 | Add sdph20.dll as affected component in description, as | indicated by above post. | Christey> Consider adding BID:2615 | View |
3085 | CVE-2001-0264 | Candidate | Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection. | Proposed (20010524) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Oliver, Wall | REVIEWING(1) Ziese | Frech> XF:bpftp-obtain-credentials(6330) | View |
3153 | CVE-2001-0332 | Candidate | Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability. | Proposed (20010524) | ACCEPT(4) Baker, Cole, Wall, Ziese | MODIFY(1) Frech | NOOP(1) Renaud | RECAST(1) Williams | REJECT(1) Magdych | REVIEWING(1) Christey | Magdych> Duplicate of CVE-0246 | Christey> While it may look like CVE-2001-0332 is a duplicate of | CVE-2001-0246, Microsoft specifically identifies two separate | variants of the same problem in its advisory, namely 0332 and | 0246. However, CD:SF-LOC currently suggests merging problems | of the same type that appear and are fixed in the same | software versions, and thus these 2 candidates *might* | in fact be duplicates - relative to CD:SF-LOC. Microsoft | needs to be consulted on this. | Williams> merge with CVE-0246 | Frech> XF:ie-frame-verification-read-files(6086) | XF:ie-frame-verification-variant(6748) | CVE-2001-0092 is also assigned to the | ie-frame-verification-files(6086), but shouldn"t be considered a | duplicate. | View |
3158 | CVE-2001-0337 | Candidate | The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. | Proposed (20010524) | ACCEPT(6) Baker, Cole, Renaud, Wall, Williams, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-webdav-lock-dos(6549) | Christey> ADDREF? BID:2736 | URL:http://www.securityfocus.com/bid/2736 | ADDREF? BUGTRAQ:20010517 def-2001-26: IIS WebDav Lock Method Memory Leak DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0170.html | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
Page 20646 of 20943, showing 5 records out of 104715 total, starting on record 103226, ending on 103230