CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5923 | CVE-2002-1539 | Candidate | Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View | |
5669 | CVE-2002-1285 | Candidate | runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments. | Proposed (20030317) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> LPRng does not contain anything called runlpr, and in fact if you | look at the packages SuSE say that they ship as part of the erratum they | don"t even provide updated LPRng packages. However they do ship lprfilter | packages and looking inside them I find that they are what contain this | runlpr program: | | http://at.rpmfind.net/opsys/linux/RPM/suse.com/i386/update/8.0/ap1/lpdfilter-0.42-155.i386.html | | This states that lpdfilter is a collection of scripts written by SuSE, and | the changelog even highlights this is where the security fix was made. | Therefore I believe that the CVE reference and all the descriptions of | this vulnerability, which are based on a bad advisory description from | SuSE, are also wrong, it should be: | | "runlpr from the SuSE lpdfilter package allows the local lp user to gain | root privileges via certain command line arguments." | View |
5928 | CVE-2002-1544 | Candidate | Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get. | Proposed (20030317) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
5929 | CVE-2002-1545 | Candidate | CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response. | Proposed (20030317) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey | Christey> This seems like a rediscovery of CVE-2001-0934. | View |
5930 | CVE-2002-1546 | Candidate | BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence. | Proposed (20030317) | ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Cox, Wall | View |
Page 20903 of 20943, showing 5 records out of 104715 total, starting on record 104511, ending on 104515