CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4164  CVE-2001-1360  Candidate  Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(2) Cox, Frech | NOOP(2) Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> I"m not sure how to vote on this, I did the research and read | the changlog and it appears that the issue you mention here has not | been fixed at all; merely documented as of sane version 1.0.5 | | Change description based on the information in the Sane tarball; note that | this affects all versions to date and is not fixed. | | ---cut--- | | - Security problems with pnm | If the pnm backend is installed and saned is used to allow users on | remote computers to scan on the local machine, pnm files can be read by | the remote user. This is limited to the files saned can access (usually | it"s running as user "sane"). All pnm files can be read if saned runs | as root which isn"t recommended anyway. The pnm backend is disabled | by default. If you want to use it, enable it with configure (see | configure --help for details). Be sure that only trusted users can | access the pnm backend over saned. | | ---cut--- | Frech> XF:sane-prm-read-files(9853)  View
4932  CVE-2002-0541  Candidate  Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581.  Proposed (20020611)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4165  CVE-2001-1361  Candidate  Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:twig-mailto(9871)  View
4166  CVE-2001-1362  Candidate  Vulnerability in the server for nPULSE before 0.53p4.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Frech    View
4167  CVE-2001-1363  Candidate  Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Frech    View

Page 20837 of 20943, showing 5 records out of 104715 total, starting on record 104181, ending on 104185

Actions