CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3261  CVE-2001-0443  Candidate  Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:qpc-popd-bo(6374)  View
3263  CVE-2001-0446  Candidate  IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:ibm-wcs-view-jsp(6308) | CONFIRM:http://www-4.ibm.com/software/webservers/appserv/doc/ | v3024/EfixWeb3024.html | Comments are cryptic.  View
3264  CVE-2001-0447  Candidate  Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:software602-lan-suite-bo(5583) | Possible duplicate or close similarity with | BID-1979/CVE-2000-1115. | Christey> The BID doesn"t look quite like this; I think it"s for | CVE-2001-0448  View
3265  CVE-2001-0448  Candidate  Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:software602-lan-suite-bo(5583) | Christey> This should be BID:2514 (and CVE-2001-0447 should have | BID:2514 removed from its set of references)  View
3267  CVE-2001-0450  Candidate  Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.  Proposed (20010524)  ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(2) Christey, Wall  Christey> Change "LIST" to "DIR" - see original post. The problem with | LIST (and NLST) occurred in Broker 3.0, not 5.0. | | The CONFIRM link is dead. | | Thanks to John Segura of secureinfo.com for noticing this.  View

Page 294 of 20943, showing 5 records out of 104715 total, starting on record 1466, ending on 1470

Actions