CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3416  CVE-2001-0603  Candidate  Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148.  Proposed (20010727)  ACCEPT(2) Baker, Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Frech> CONFIRM:Lotus SPR #CBRN4QWJUN at | http://www.notes.net/qmrdown.nsf/QMRWelcome  View
3417  CVE-2001-0604  Candidate  Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of "/" characters.  Proposed (20010727)  ACCEPT(2) Baker, Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Frech> CONFIRM:http://www.notes.net/qmrdown.nsf/QMRWelcome; Lotus | does not seem to wax prolific with their DoS explanations. For 5.0.7, | any of these SPR#s have the explanation "Fixed a potential Denial of | Service attack on HTTP.": JCHN4TQS2T, JCHN4RPKC2, JCHN4TQNL8, | JCHN4JQKYQ, JCHN4TGN32.  View
3418  CVE-2001-0605  Candidate  Headlight Software MyGetright prior to 1.0b allows a remote attacker to upload and/or overwrite arbitrary files via a malicious .dld (skins-data) file which contains long strings of random data.  Proposed (20010727)  MODIFY(1) Frech | NOOP(5) Cole, Foat, Prosser, Wall, Ziese | REVIEWING(2) Bishop, Williams  Frech> XF:mygetright-skin-overwrite-file(6155) | In description, product should be "My GetRight" (see | http://www.mygetright.com/get.html) | Prosser> According to Discover"s Bulletin, the vendor, www.mygetright.com acknowledged the problem and fixed it in version 1.0b. However, vendor page makes no mention of this issue.  View
3423  CVE-2001-0610  Candidate  kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop    View
3427  CVE-2001-0614  Candidate  Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Christey> Give the particular nature of the constructed URL, i.e. the | command is specified in the VBEXE parameter.  View

Page 282 of 20943, showing 5 records out of 104715 total, starting on record 1406, ending on 1410

Actions