CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4130  CVE-2001-1326  Candidate  Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:eudora-msviewer-execute-attachment(6635)  View
4133  CVE-2001-1329  Candidate  Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root priveleges via a long command line argument.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REJECT(1) Christey  Christey> Acknowledged by vendor (Troy Bollinger no less ;-) in: | BUGTRAQ:20010612 Re: (forw) rsh bufferoverflow on AIX 4.2 | URL:http://online.securityfocus.com/archive/1/190630 | | HOWEVER... this looks like a rediscovery of CVE-1999-0101. | Troy"s June 2001 response mentions a gethostbyname() problem | in 1996, which is CVE-1999-0101. | Frech> XF:dns-leng-ovf(637) | XF:ghbn-bo(1751) | Also assigned: CVE-1999-0101 | In description, "privileges" is misspelled.  View
4645  CVE-2002-0253  Candidate  PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> Is this another case when PHP leaks path information by design, | as supported by "display_errors" option? Then the | vulnerability (rather, exposure) would be in the use of the | display_errors option itself, whose implications may include | this particular scenario. | CHANGE> [Cox changed vote from REVIEWING to NOOP]  View
4134  CVE-2001-1330  Candidate  Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.  Proposed (20020502)  ACCEPT(1) Green | NOOP(4) Cole, Cox, Foat, Wall | REJECT(2) Christey, Frech  Christey> Reject this for 2 reasons: | (1) It"s a carbon copy of CVE-2001-1329 | (2) CVE-2001-1329 is a dupe of CVE-1999-0101, which means | CVE-2001-1330 is, too. | Frech> CVE-2001-1330 is the same as CVE-2001-1329  View
4646  CVE-2002-0254  Candidate  ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetails.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:icq-large-jpg-bo(8159)  View

Page 20800 of 20943, showing 5 records out of 104715 total, starting on record 103996, ending on 104000

Actions