CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3550  CVE-2001-0743  Candidate  Paging function in O"Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped " character followed by JavaScript commands.  Proposed (20011012)  MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Foat, Oliver, Wall  Frech> XF:webboard-pager-javascript-dos(6653) | Christey> Need to re-examine this; sounds like XSS to me on a second | glance at the Bugtraq post.  View
3551  CVE-2001-0744  Candidate  Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.  Proposed (20011012)  ACCEPT(4) Armstrong, Baker, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:horde-popen-remote-access(5244) | Christey> Need to examine the codebase relationship between Horde and | IMP. | Christey> BID:3066 | URL:http://online.securityfocus.com/bid/3066  View
3553  CVE-2001-0746  Candidate  Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.  Proposed (20011012)  ACCEPT(6) Armstrong, Baker, Cole, Foat, Frech, Wall | NOOP(1) Christey  Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE.  View
3554  CVE-2001-0747  Candidate  Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request.  Proposed (20011012)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:netscape-enterprise-uri-bo(6554) | Christey> HP:HPSBUX0106-152 might address CVE-2001-0746 or | CVE-2001-0747, or maybe neither, but only HP knows for sure. | See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html | Christey> I am about to create a separate candidate for the HP advisory. | Obviously that advisory is affected by CD:VAGUE.  View
3563  CVE-2001-0756  Candidate  CatalogMgr.pl in VirtualCatalog (incorrectly claimed to be in VirtualCart) allows remote attackers to execute arbitrary code via the template parameter.  Proposed (20011012)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:virtualcatalog-command-execution(6663)  View

Page 20747 of 20943, showing 5 records out of 104715 total, starting on record 103731, ending on 103735

Actions