CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3574  CVE-2001-0767  Candidate  Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.  Proposed (20011012)  ACCEPT(3) Armstrong, Cole, Foat | NOOP(2) Christey, Wall | REJECT(1) Frech  Frech> DUPE CVE-2000-0640 | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002  View
3575  CVE-2001-0768  Candidate  GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.  Proposed (20011012)  ACCEPT(2) Baker, Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Baker> Vendor added password encryption in latest version, 0.996, and you can see the comments in the changes log, at the following URL: | | www.nitrolic.com/main.htm | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002  View
3578  CVE-2001-0771  Candidate  Spytech SpyAnywhere 1.50 allows remote attackers to gain administrator access via a single character in the "loginpass" field.  Proposed (20011012)  ACCEPT(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Christey> fix typo: "a a"  View
3583  CVE-2001-0776  Candidate  Buffer overflow in DynFX MailServer version 2.10 allows remote attackers to conduct a denial of service via a long username to the POP3 service.  Proposed (20011012)  ACCEPT(2) Armstrong, Frech | NOOP(3) Cole, Foat, Wall    View
3614  CVE-2001-0808  Candidate  gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.  Proposed (20011122)  ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(3) Armstrong, Foat, Wall  Bishop> If the SPECIFIC nature of the problem is determined to be both, I would | accept two separate candidates. But in the absence of this information, | I favor accepting it now rather than waiting for details. We can always | revisit it later.  View

Page 20749 of 20943, showing 5 records out of 104715 total, starting on record 103741, ending on 103745

Actions