CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3437  CVE-2001-0624  Candidate  QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop    View
3445  CVE-2001-0632  Candidate  Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.  Proposed (20010727)  ACCEPT(6) Baker, Bishop, Cole, Prosser, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF: chilisoft-asp-unauthorized-access(6957) | CHANGE> [Williams changed vote from ACCEPT to MODIFY] | Williams> there are actually several issues here, not just the one mentioned in our description. need to modify. | CHANGE> [Williams changed vote from MODIFY to ACCEPT] | Williams> NM my comments. just saw the other CANs. :/ | Prosser> | Vendor Response to issue: | Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities | http://www.securityfocus.com/archive/1/20010224172142.1888.qmail@securityfocus.com  View
3446  CVE-2001-0633  Candidate  Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a ".." (dot dot) attack in the sample script "codebrws.asp".  Proposed (20010727)  ACCEPT(4) Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(3) Baker, Foat, Wall  Frech> XF:chilisoft-asp-view-files(6137) | CHANGE> [Baker changed vote from REVIEWING to NOOP]  View
3315  CVE-2001-0498  Candidate  Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.  Proposed (20010727)  ACCEPT(5) Armstrong, Cole, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_dos.pdf | CVE-2001-0498 possible dupe of CVE-2001-0515, which is already | assigned to oracle-listener-offsettodata-dos(6713) | Prosser> Discover of issue (NAI) indicates that Oracle produced a patch for this issue. Oracle patch site is restricted, but taking NAI"s word as verification. | Christey> Consider adding BID:2940  View
3083  CVE-2001-0262  Candidate  Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.  Proposed (20010524)  ACCEPT(3) Baker, Cole, Williams | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese  Frech> XF:netscape-smartdownload-sdph20-bo(6403) | Christey> BUGTRAQ:20010418 Netscape SmartDownload 1.3 Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/177589 | Add sdph20.dll as affected component in description, as | indicated by above post. | Christey> Consider adding BID:2615  View

Page 284 of 20943, showing 5 records out of 104715 total, starting on record 1416, ending on 1420

Actions