CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1497  CVE-1999-1517  Candidate  runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:amanda-runtar(3402)  View
2621  CVE-2000-1052  Candidate  Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.  Proposed (20001129)  ACCEPT(3) Armstrong, Cole, Mell | MODIFY(1) Frech  Frech> XF:allaire-jrun-ssifilter-url(5405)  View
2554  CVE-2000-0985  Candidate  Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.  Proposed (20001129)  ACCEPT(2) Baker, Mell | MODIFY(1) Frech | NOOP(1) Cole  Frech> XF:all-mail-smtp-bo(5360)  View
2202  CVE-2000-0626  Candidate  Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.  Proposed (20000803)  ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey  Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers.  View
4058  CVE-2001-1254  Candidate  Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:alexis-http-plaintext-information(7205)  View

Page 211 of 20943, showing 5 records out of 104715 total, starting on record 1051, ending on 1055

Actions