CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5923  CVE-2002-1539  Candidate  Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
5669  CVE-2002-1285  Candidate  runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox  CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> LPRng does not contain anything called runlpr, and in fact if you | look at the packages SuSE say that they ship as part of the erratum they | don"t even provide updated LPRng packages. However they do ship lprfilter | packages and looking inside them I find that they are what contain this | runlpr program: | | http://at.rpmfind.net/opsys/linux/RPM/suse.com/i386/update/8.0/ap1/lpdfilter-0.42-155.i386.html | | This states that lpdfilter is a collection of scripts written by SuSE, and | the changelog even highlights this is where the security fix was made. | Therefore I believe that the CVE reference and all the descriptions of | this vulnerability, which are based on a bad advisory description from | SuSE, are also wrong, it should be: | | "runlpr from the SuSE lpdfilter package allows the local lp user to gain | root privileges via certain command line arguments."  View
5928  CVE-2002-1544  Candidate  Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.  Proposed (20030317)  NOOP(4) Armstrong, Cole, Cox, Wall    View
5929  CVE-2002-1545  Candidate  CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.  Proposed (20030317)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> This seems like a rediscovery of CVE-2001-0934.  View
5930  CVE-2002-1546  Candidate  BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence.  Proposed (20030317)  ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Cox, Wall    View

Page 20903 of 20943, showing 5 records out of 104715 total, starting on record 104511, ending on 104515

Actions