CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3520 | CVE-2001-0712 | Candidate | The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc. | Proposed (20011012) | ACCEPT(2) Baker, Cole | NOOP(1) Armstrong | REJECT(2) Foat, Frech | REVIEWING(1) Wall | Baker> I would argue that a browser executing a script when it shouldn"t is still a vulnerability. If it is supposed to be a non-scriptable file type, and that fails, resulting in a script being executed without the user"s knowledge, then it is a problem, and thus should be included as a vulnerability. I vote this should be accepted, and if Microsoft acknowledges this in their follow up, then you have vendor acknowledgement of the problem as well. | Foat> The candidate does not meet the criteria for a vulnerability or | exposure, even though it describes an unexpected behavior. | View |
3541 | CVE-2001-0734 | Candidate | Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine. | Proposed (20011012) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Frech | NOOP(1) Wall | View | |
3542 | CVE-2001-0735 | Candidate | Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file. | Proposed (20011012) | ACCEPT(4) Armstrong, Baker, Foat, Frech | NOOP(2) Cole, Wall | View | |
3544 | CVE-2001-0737 | Candidate | A long "synch" delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack. | Proposed (20011012) | ACCEPT(3) Armstrong, Foat, Frech | NOOP(2) Cole, Wall | View | |
3549 | CVE-2001-0742 | Candidate | Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command. | Proposed (20011012) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:cmail-helo-bo(7406) | View |
Page 20746 of 20943, showing 5 records out of 104715 total, starting on record 103726, ending on 103730