CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3233 | CVE-2001-0415 | Candidate | REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts. | Proposed (20010524) | ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese | View | |
3235 | CVE-2001-0417 | Candidate | Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files. | Proposed (20010524) | ACCEPT(3) Baker, Cole, Ziese | NOOP(1) Wall | REJECT(3) Christey, Frech, Oliver | Frech> DUPLICATE OF CVE-2001-0036: KTH Kerberos IV allows local users to | overwrite arbitrary files via a symlink attack on a ticket file. | Oliver> Appears to be a subset of CVE-2001-036. | Christey> Change description to point out that the Kerberos 5 package is | affected. | FREEBSD:FreeBSD-SA-01:25 | Also ensure that the other problems described in the FreeBSD | advisory have CANs/CVEs. | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> Agree that these are dupes. Since CVE-2001-0036 is already | an official CVE entry, this candidate will be rejected. | This CAN"s references will be added to CVE-2001-0036. | View |
3236 | CVE-2001-0418 | Candidate | content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:ncm-content-database-access(6386) | View |
3237 | CVE-2001-0419 | Candidate | Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:oracle-appserver-ndwfn4-bo(6334) | Christey> At http://otn.oracle.com/deploy/security/alerts.htm, | in an item titled "Oracle Application Server Buffer Overflow," | Oracle says that it was "Unable to reproduce vulnerability" | View |
3238 | CVE-2001-0420 | Candidate | Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547 | View |
Page 291 of 20943, showing 5 records out of 104715 total, starting on record 1451, ending on 1455