CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3731 | CVE-2001-0925 | Candidate | The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Green | NOOP(2) Christey, Wall | REJECT(1) Frech | Frech> I"m using both candidates until we decide if it is a dupe, | and then which | candidate to deprecate. | Christey> BUGTRAQ:20010615 TSLSA-2001-0010 - Apache | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0180.html | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately. | View |
1047 | CVE-1999-1067 | Candidate | SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(2) Cole, Foat | Frech> I"d be a lot more confident in this vote if there was a more | concrete reference strongly associating webdist.cgi and machineinfo. | View |
1225 | CVE-1999-1245 | Candidate | vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> http://www.securityfocus.com/archive/1/13130 | View |
3791 | CVE-2001-0986 | Candidate | SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(2) Cole, Foat | REVIEWING(1) Wall | Frech> http://www.kb.cert.org/vuls/id/914859 | View |
1535 | CVE-1999-1555 | Candidate | Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan"s antivirus update feature to install a Trojan horse dll. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> http://support.cai.com/Download/patches/inocnt.html | View |
Page 229 of 20943, showing 5 records out of 104715 total, starting on record 1141, ending on 1145