CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3261 | CVE-2001-0443 | Candidate | Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:qpc-popd-bo(6374) | View |
3263 | CVE-2001-0446 | Candidate | IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:ibm-wcs-view-jsp(6308) | CONFIRM:http://www-4.ibm.com/software/webservers/appserv/doc/ | v3024/EfixWeb3024.html | Comments are cryptic. | View |
3264 | CVE-2001-0447 | Candidate | Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | Frech> XF:software602-lan-suite-bo(5583) | Possible duplicate or close similarity with | BID-1979/CVE-2000-1115. | Christey> The BID doesn"t look quite like this; I think it"s for | CVE-2001-0448 | View |
3265 | CVE-2001-0448 | Candidate | Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | Frech> XF:software602-lan-suite-bo(5583) | Christey> This should be BID:2514 (and CVE-2001-0447 should have | BID:2514 removed from its set of references) | View |
3267 | CVE-2001-0450 | Candidate | Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name. | Proposed (20010524) | ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(2) Christey, Wall | Christey> Change "LIST" to "DIR" - see original post. The problem with | LIST (and NLST) occurred in Broker 3.0, not 5.0. | | The CONFIRM link is dead. | | Thanks to John Segura of secureinfo.com for noticing this. | View |
Page 294 of 20943, showing 5 records out of 104715 total, starting on record 1466, ending on 1470