CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4130 | CVE-2001-1326 | Candidate | Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:eudora-msviewer-execute-attachment(6635) | View |
4133 | CVE-2001-1329 | Candidate | Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root priveleges via a long command line argument. | Proposed (20020502) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REJECT(1) Christey | Christey> Acknowledged by vendor (Troy Bollinger no less ;-) in: | BUGTRAQ:20010612 Re: (forw) rsh bufferoverflow on AIX 4.2 | URL:http://online.securityfocus.com/archive/1/190630 | | HOWEVER... this looks like a rediscovery of CVE-1999-0101. | Troy"s June 2001 response mentions a gethostbyname() problem | in 1996, which is CVE-1999-0101. | Frech> XF:dns-leng-ovf(637) | XF:ghbn-bo(1751) | Also assigned: CVE-1999-0101 | In description, "privileges" is misspelled. | View |
4645 | CVE-2002-0253 | Candidate | PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path. | Proposed (20020502) | ACCEPT(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> Is this another case when PHP leaks path information by design, | as supported by "display_errors" option? Then the | vulnerability (rather, exposure) would be in the use of the | display_errors option itself, whose implications may include | this particular scenario. | CHANGE> [Cox changed vote from REVIEWING to NOOP] | View |
4134 | CVE-2001-1330 | Candidate | Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument. | Proposed (20020502) | ACCEPT(1) Green | NOOP(4) Cole, Cox, Foat, Wall | REJECT(2) Christey, Frech | Christey> Reject this for 2 reasons: | (1) It"s a carbon copy of CVE-2001-1329 | (2) CVE-2001-1329 is a dupe of CVE-1999-0101, which means | CVE-2001-1330 is, too. | Frech> CVE-2001-1330 is the same as CVE-2001-1329 | View |
4646 | CVE-2002-0254 | Candidate | ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetails. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:icq-large-jpg-bo(8159) | View |
Page 20800 of 20943, showing 5 records out of 104715 total, starting on record 103996, ending on 104000