CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5461  CVE-2002-1073  Candidate  Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.  Proposed (20020830)  ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> The vendor confirmed this issue via email on August 30: | "The vulnerability report was correct. The problem are fixed in the | mercur control service version <4.02.01>. This version of the mercur | control service are integrated in the current download version of | Mercur Mailserver 4.2."  View
5839  CVE-2002-1455  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.  Proposed (20030317)  NOOP(4) Christey, Cole, Cox, Wall  Christey> The redir.exe issue involves XSS, but it also involves newline | injection. Should it be SPLIT from this CAN? | | XF:omnihttpd-test-sample-xss(9961) | URL:http://www.iss.net/security_center/static/9961.php | BID:5568 | URL:http://www.securityfocus.com/bid/5568  View
4825  CVE-2002-0433  Candidate  Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(5) Cole, Cox, Foat, Green, Wall | REVIEWING(1) Christey  Christey> The Pi3Web author, Holger Zimmermann, sent an email on | 20041125 disputing this claim. Therefore, this candidate may need to | be REJECTed.  View
3537  CVE-2001-0729  Candidate  Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.  Modified (20071115)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View
2923  CVE-2001-0102  Candidate  "Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Christey> The following post claims that Apple fixed the problem. | However, the web page is broken, and the new page requires | user registration. | BUGTRAQ:20010420 [FYI] Mac OS 9 Multiple Users weakness fixed (was: Mac OS 9 Multiple Users Control Panel Password Vulnerability) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98793967806147&w=2  View

Page 287 of 20943, showing 5 records out of 104715 total, starting on record 1431, ending on 1435

Actions