CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3437  CVE-2001-0624  Candidate  QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop    View
3445  CVE-2001-0632  Candidate  Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.  Proposed (20010727)  ACCEPT(6) Baker, Bishop, Cole, Prosser, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF: chilisoft-asp-unauthorized-access(6957) | CHANGE> [Williams changed vote from ACCEPT to MODIFY] | Williams> there are actually several issues here, not just the one mentioned in our description. need to modify. | CHANGE> [Williams changed vote from MODIFY to ACCEPT] | Williams> NM my comments. just saw the other CANs. :/ | Prosser> | Vendor Response to issue: | Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities | http://www.securityfocus.com/archive/1/20010224172142.1888.qmail@securityfocus.com  View
3446  CVE-2001-0633  Candidate  Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a ".." (dot dot) attack in the sample script "codebrws.asp".  Proposed (20010727)  ACCEPT(4) Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(3) Baker, Foat, Wall  Frech> XF:chilisoft-asp-view-files(6137) | CHANGE> [Baker changed vote from REVIEWING to NOOP]  View
3315  CVE-2001-0498  Candidate  Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.  Proposed (20010727)  ACCEPT(5) Armstrong, Cole, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_dos.pdf | CVE-2001-0498 possible dupe of CVE-2001-0515, which is already | assigned to oracle-listener-offsettodata-dos(6713) | Prosser> Discover of issue (NAI) indicates that Oracle produced a patch for this issue. Oracle patch site is restricted, but taking NAI"s word as verification. | Christey> Consider adding BID:2940  View
3365  CVE-2001-0552  Candidate  ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.  Proposed (20010829)  ACCEPT(6) Armstrong, Baker, Bishop, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Prosser> HP:HPSBUX0106-154 and http://www.cert.org/advisories/CA-2001-24.html | Frech> XF:openview-nnm-ovactiond-execution(6683)  View

Page 20667 of 20943, showing 5 records out of 104715 total, starting on record 103331, ending on 103335

Actions