CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3313 | CVE-2001-0496 | Candidate | kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges. | Modified (20010910-01) | ACCEPT(4) Baker, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Renaud, Wall | REVIEWING(1) Christey | Williams> kdesu is part of kdelibs package. since entire kdelibs package must be upgraded, and since kdelibs (rather than kdesu) is referenced in most advisories related to this issue, we might want to reference kdelibs in this CAN. | Frech> XF:kdelibs-kdesu-insecure-tmpfile(6856) | Christey> Agree with Ken Williams. The CVE descriptions in general | should capture all "reasonable" keywords under which | someone may know the vulnerability. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> It"s possible that this is the same vulnerability as CVE-2001-0178, | but the description is written so differently from the others, that | it"s hard to be sure. In addition, Mandrake released a separate | advisory for CVE-2001-0178. | BID:2669 addresses CVE-2001-0178. | View |
8442 | CVE-2004-0014 | Candidate | Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings. | Modified (20071113) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall | Williams> need to change desc. i think this was fixed in 0.8.2. | http://www.gohome.org/nd | View |
3301 | CVE-2001-0484 | Candidate | Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages. | Modified (20020223-01) | ACCEPT(1) Renaud | MODIFY(2) Baker, Frech | NOOP(6) Balinsky, Cole, Oliver, Wall, Williams, Ziese | REVIEWING(1) Christey | Williams> there was an issue with admin passwd storage for Tektronix Phaser 360, 740, 780, 840 | Frech> XF:tektronix-phaserlink-webserver-backdoor(6482) | Baker> 750DP and 930 printers should be added | http://www.securityfocus.com/archive/1/181007 | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> CVE-1999-1508 covered the older versions discussed | by Ken Williams. These may be duplicates. | This one is BID:2659 | http://www.securityfocus.com/bid/2659 | View |
3956 | CVE-2001-1152 | Candidate | Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters. | Proposed (20020315) | ACCEPT(2) Baker, Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Green, Wall | REJECT(1) Ziese | Ziese> ACCEPT REASON: Rejection logic makes sense, products have to be used as | intended. Misuse is not a security vulnerability per se. | Frech> XF:content-slash-bypass-filter(6816) | Baker> I would say that this is a vulnerability, since their website | touts URL filtering as a feature of the product. If the product has to | filter URL"s then the product needs to be able to filter URL"s properly, | or the product fails. | Here is the list of features, quoted from their product page for | web sweeper: | | "Key Features | Policy based web security implementation for information posted to and downloaded from the web | Protects against unauthorized users accessing the web utilizing user authentication | Provides URL filtering blocking stopping inappropriate site access | Protects against loss of confidential information, viruses, portable code, and inappropriate content entering and | leaving via web based e-mail accounts such as hotmail and Yahoo | Auditing and reporting on individual and group web traffic | Customizable "Block" and "Progress Message" pages " | View |
4025 | CVE-2001-1221 | Candidate | D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of "public" which allows remote attackers to gain sensitive information. | Proposed (20020315) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REJECT(1) Ziese | Ziese> candidate? | Frech> XF:nwn-ap-default-snmp-read(6559) | View |
Page 20942 of 20943, showing 5 records out of 104715 total, starting on record 104706, ending on 104710