CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3244  CVE-2001-0426  Candidate  Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.  Proposed (20010524)  ACCEPT(1) Dik | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese  Frech> XF:solaris-dtsession-bo(6366) | Dik> sun bug: 4448598  View
3249  CVE-2001-0431  Candidate  Vulnerability in iPlanet Web Server Enterprise Edition 4.x.  Proposed (20010524)  ACCEPT(3) Baker, Cole, Ziese | NOOP(1) Wall | REJECT(1) Frech  Frech> Duplicate of CVE-2001-0327.  View
3250  CVE-2001-0432  Candidate  Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.  Proposed (20010524)  ACCEPT(1) Ziese | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:interscan-viruswall-isadmin-bo(6368)  View
3251  CVE-2001-0433  Candidate  Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Christey  Frech> XF:savant-get-bo(4901) | Christey> Should CVE-2002-0099 and/or CVE-2001-0433 be MERGED with | CVE-2000-0641? All describe slightly different overflows | that, perhaps, should be merged according to CD:SF-LOC. | It depends on which versions are affected, which would require | some vendor acknowledgement or consultation. | | A vague changelog for version 3.1 at | http://sourceforge.net/project/shownotes.php?release_id=75333 says | "security fixes" but it"s not clear *which* security fixes | were made. | | The description for CVE-2000-0641 is slightly incorrect. The | exploit is clearly due to a large number of headers, not | arguments to the GET request itself. So, CVE-2000-0641 | clearly overlaps with CVE-2001-0433. | | The exploit for CVE-2001-0433 also doesn"t really have | anything to do with a "cgi-test.pl" program (which isn"t in | the distribution). The discloser simply used that as an | example program of a long request.  View
3253  CVE-2001-0435  Candidate  The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese  Frech> XF:nai-pgp-split-keys(6341)  View

Page 20654 of 20943, showing 5 records out of 104715 total, starting on record 103266, ending on 103270

Actions