CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5461 | CVE-2002-1073 | Candidate | Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password. | Proposed (20020830) | ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Foat, Wall | Christey> The vendor confirmed this issue via email on August 30: | "The vulnerability report was correct. The problem are fixed in the | mercur control service version <4.02.01>. This version of the mercur | control service are integrated in the current download version of | Mercur Mailserver 4.2." | View |
5839 | CVE-2002-1455 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe. | Proposed (20030317) | NOOP(4) Christey, Cole, Cox, Wall | Christey> The redir.exe issue involves XSS, but it also involves newline | injection. Should it be SPLIT from this CAN? | | XF:omnihttpd-test-sample-xss(9961) | URL:http://www.iss.net/security_center/static/9961.php | BID:5568 | URL:http://www.securityfocus.com/bid/5568 | View |
4825 | CVE-2002-0433 | Candidate | Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character. | Proposed (20020611) | ACCEPT(1) Frech | NOOP(5) Cole, Cox, Foat, Green, Wall | REVIEWING(1) Christey | Christey> The Pi3Web author, Holger Zimmermann, sent an email on | 20041125 disputing this claim. Therefore, this candidate may need to | be REJECTed. | View |
3537 | CVE-2001-0729 | Candidate | Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters. | Modified (20071115) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately. | View |
2923 | CVE-2001-0102 | Candidate | "Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | Christey> The following post claims that Apple fixed the problem. | However, the web page is broken, and the new page requires | user registration. | BUGTRAQ:20010420 [FYI] Mac OS 9 Multiple Users weakness fixed (was: Mac OS 9 Multiple Users Control Panel Password Vulnerability) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98793967806147&w=2 | View |
Page 287 of 20943, showing 5 records out of 104715 total, starting on record 1431, ending on 1435