CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4696  CVE-2002-0304  Candidate  Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.  Modified (20050705)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> VULNWATCH:20020222 [VulnWatch] SecurityOffice Security Advisories: Essentia and LilHTTP web servers | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0051.html | XF:lilhttp-protected-file-access(8247) | URL:http://www.iss.net/security_center/static/8247.php | BID:4153 | URL:http://www.securityfocus.com/bid/4153 | Frech> XF:lilhttp-protected-file-access(8247)  View
4536  CVE-2002-0142  Candidate  CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long and ends in a series of . (dot) characters.  Proposed (20020315)  ACCEPT(3) Cole, Frech, Green | NOOP(4) Balinsky, Christey, Foat, Wall  Christey> VULNWATCH:20020113 Pi3Web Webserver v2.0 Buffer Overflow Vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0015.html  View
3977  CVE-2001-1173  Candidate  Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.  Proposed (20020315)  ACCEPT(5) Armstrong, Baker, Cole, Green, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps) | URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:masqmail-gain-privileges(8717)  View
1849  CVE-2000-0271  Candidate  read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.  Proposed (20000426)  ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall  Christey> Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | ADDREF XF:emacs-password-history | Frech> XF:emacs-password-history | Levy> Change BID reference to BID 1127  View
2532  CVE-2000-0963  Candidate  Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.  Modified (20080819)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey  Christey> Various vendor writeups indicate that there are multiple | overflows, so maybe this needs to be SPLIT. | | ADDREF FREEBSD:FreeBSD-SA-00:68 | ADDREF DEBIAN:20001121 ncurses: local privilege escalation | http://www.debian.org/security/2000/20001121 | ADDREF REDHAT:RHSA-2000:115 | http://www.redhat.com/support/errata/RHSA-2000-115.html | BUGTRAQ:20001201 Immunix OS Security update for ncurses | http://marc.theaimsgroup.com/?l=bugtraq&m=97570745306444&w=2 | Frech> XF:libmytinfo-bo(4422) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> This is all a library issue in which TERM/TERMINFO_DIRS are | one possible attack vector, but another is through entries | in the .terminfo file. Add .terminfo and termcap to the | description, as well as libncurses. | | ADDREF MANDRAKE:MDKSA-2001:052 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-052.php3 | | Now need to examine whether this is a dupe of CVE-2002-0062, | and/or BID:2116. There"s certainly enough confusion to go | around. | CHANGE> [Christey changed vote from REVIEWING to NOOP] | Christey> This is not a dupe of CVE-2002-0062. As explained in | DEBIAN:DSA-113, the original patches for CVE-2000-0963 | didn"t catch every problem. | | ADDREF SUSE:SuSE-SA:2000:043 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97267560724404&w=2 | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View

Page 279 of 20943, showing 5 records out of 104715 total, starting on record 1391, ending on 1395

Actions