CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4808  CVE-2002-0416  Candidate  Buffer overflow in SH39 MailServer 1.21 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long command to the SMTP port.  Proposed (20020611)  ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> Article title for BUGTRAQ:20020305 is "Buffer Overflows in | sh39.com"s mailserver 1.21".  View
4809  CVE-2002-0417  Candidate  Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4810  CVE-2002-0418  Candidate  Directory traversal vulnerability in the com.endymion.sake.servlet.mail.MailServlet servlet for Endymion SakeMail 1.0.36 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the param_name parameter.  Proposed (20020611)  ACCEPT(2) Alderson, Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4812  CVE-2002-0420  Candidate  Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4813  CVE-2002-0421  Candidate  IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View

Page 20850 of 20943, showing 5 records out of 104715 total, starting on record 104246, ending on 104250

Actions