CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1273 | CVE-1999-1293 | Candidate | mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. | Proposed (20010912) | ACCEPT(3) Armstrong, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:apache-mod-proxy-dos(7249) | CONFIRM reference no longer seems to exist. BugTraq message | seems to be a confirmation/advisory, however. | CHANGE> [Foat changed vote from ACCEPT to NOOP] | View |
2771 | CVE-2000-1204 | Candidate | Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root. | Proposed (20020830) | ACCEPT(5) Armstrong, Baker, Cole, Cox, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:apache-modvhostalias-source-disclosure(11088) | View |
2772 | CVE-2000-1205 | Candidate | Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant. | Modified (20070926) | ACCEPT(7) Armstrong, Baker, Cole, Cox, Foat, Green, Wall | MODIFY(1) Frech | Frech> XF:apache-printenv-xss(10938) | View |
2773 | CVE-2000-1206 | Candidate | Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:apache-virtualhosting-obtain-files(11139) | View |
1473 | CVE-1999-1493 | Candidate | Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk(). | Modified (20020308-01) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:apollo-crp-root-access(7158) | View |
Page 20737 of 20943, showing 5 records out of 104715 total, starting on record 103681, ending on 103685