CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3417  CVE-2001-0604  Candidate  Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of "/" characters.  Proposed (20010727)  ACCEPT(2) Baker, Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Frech> CONFIRM:http://www.notes.net/qmrdown.nsf/QMRWelcome; Lotus | does not seem to wax prolific with their DoS explanations. For 5.0.7, | any of these SPR#s have the explanation "Fixed a potential Denial of | Service attack on HTTP.": JCHN4TQS2T, JCHN4RPKC2, JCHN4TQNL8, | JCHN4JQKYQ, JCHN4TGN32.  View
1041  CVE-1999-1061  Candidate  HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.  Proposed (20010912)  ACCEPT(2) Cole, Frech | NOOP(1) Foat  Frech> CONFIRM:http://www.hp.com/cposupport/printers/support_doc/bpl | 02914.html  View
3375  CVE-2001-0562  Candidate  a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.  Proposed (20010727)  ACCEPT(3) Cole, Frech, Ziese | NOOP(4) Bishop, Christey, Foat, Wall  Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description. | CHANGE> [Bishop changed vote from REVIEWING to NOOP] | Christey> The URL recommended by Andre is *probably* addressing this | problem, but it"s not quite certain. There is insufficient | detail to determine if the vendor has truly acknowledged the | problem. I have an email to a1stats@gadnet.com to see | if I can confirm. | | This is affected by CD:SF-EXEC since multiple executables in the same | package are affected (a1disp.cgi, a1disp2.cgi, a1disp4.cgi, and | a1disp3.cgi). | Christey> Received confirmation via email, 2/26/2002.  View
3374  CVE-2001-0561  Candidate  Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a ".." (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.  Modified (20050509)  ACCEPT(3) Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Bishop  Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description.  View
4639  CVE-2002-0247  Candidate  Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.  Proposed (20020502)  ACCEPT(4) Armstrong, Cole, Frech, Wall | NOOP(2) Cox, Foat  Frech> CONFIRM:http://www.debian.org/security/2002/dsa-108  View

Page 235 of 20943, showing 5 records out of 104715 total, starting on record 1171, ending on 1175

Actions