CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3233  CVE-2001-0415  Candidate  REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View
3235  CVE-2001-0417  Candidate  Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.  Proposed (20010524)  ACCEPT(3) Baker, Cole, Ziese | NOOP(1) Wall | REJECT(3) Christey, Frech, Oliver  Frech> DUPLICATE OF CVE-2001-0036: KTH Kerberos IV allows local users to | overwrite arbitrary files via a symlink attack on a ticket file. | Oliver> Appears to be a subset of CVE-2001-036. | Christey> Change description to point out that the Kerberos 5 package is | affected. | FREEBSD:FreeBSD-SA-01:25 | Also ensure that the other problems described in the FreeBSD | advisory have CANs/CVEs. | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> Agree that these are dupes. Since CVE-2001-0036 is already | an official CVE entry, this candidate will be rejected. | This CAN"s references will be added to CVE-2001-0036.  View
3236  CVE-2001-0418  Candidate  content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:ncm-content-database-access(6386)  View
3237  CVE-2001-0419  Candidate  Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:oracle-appserver-ndwfn4-bo(6334) | Christey> At http://otn.oracle.com/deploy/security/alerts.htm, | in an item titled "Oracle Application Server Buffer Overflow," | Oracle says that it was "Unable to reproduce vulnerability"  View
3238  CVE-2001-0420  Candidate  Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547  View

Page 291 of 20943, showing 5 records out of 104715 total, starting on record 1451, ending on 1455

Actions