CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3714 | CVE-2001-0908 | Candidate | CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT). | Proposed (20020131) | ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | View | |
3716 | CVE-2001-0910 | Candidate | Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup. | Proposed (20020131) | ACCEPT(2) Armstrong, Frech | NOOP(3) Cole, Foat, Wall | View | |
3717 | CVE-2001-0911 | Candidate | PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it. | Proposed (20020131) | ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | View | |
3719 | CVE-2001-0913 | Candidate | Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers. | Proposed (20020131) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:rwhoisd-syslog-format-string(7597) | View |
3729 | CVE-2001-0923 | Candidate | RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried. | Proposed (20020131) | ACCEPT(2) Baker, Frech | NOOP(4) Armstrong, Cole, Foat, Wall | View |
Page 20757 of 20943, showing 5 records out of 104715 total, starting on record 103781, ending on 103785