CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3049 | CVE-2001-0228 | Candidate | Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request. | Proposed (20010309) | MODIFY(1) Frech | NOOP(2) Lawler, Ziese | Frech> XF:goahead-directory-traversal(6046) | View |
3050 | CVE-2001-0229 | Candidate | Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts. | Proposed (20010309) | ACCEPT(1) Lawler | MODIFY(1) Frech | NOOP(1) Ziese | Frech> XF:chilisoft-asp-elevate-privileges(6072) | View |
3053 | CVE-2001-0232 | Candidate | newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters. | Proposed (20010309) | MODIFY(1) Frech | NOOP(2) Lawler, Ziese | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:newsdesk-metacharacter-command-execution(8377) | View |
785 | CVE-1999-0805 | Candidate | Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests. | Proposed (20010214) | ACCEPT(2) Baker, Frech | NOOP(2) Christey, Cole | Christey> BID:276 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=276 | Frech> XF:novell-tts-dos | View |
1890 | CVE-2000-0312 | Candidate | cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron"s fake popen function. | Proposed (20010214) | ACCEPT(3) Baker, Cole, Collins | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:cron-sendmail-root(3335) | Seems like this issue is not just OpenBSD, and is described | differently by other vendors: | SuSE Security Announcement #15 Security hole in cron | http://www.suse.de/de/support/security/suse_security_announce_15.txt | Red Hat, Inc. Security Advisory RHSA-1999:030-02 Buffer overflow in | cron daemon | http://www.redhat.com/support/errata/rh52-errata-general.html#vixie-cron | Caldera Systems, Inc. Security Advisory CSSA-1999-023.0 serious security | problem in cron | http://www.calderasystems.com/support/security/advisories/CSSA-1999-023.0.tx | t | All are dated on or around 1999-08-27 to 1999-08-30. | Also, may overlap with CVE-1999-0769: Vixie Cron on Linux systems allows | local users to set parameters of sendmail commands via the MAILTO | environmental variable. | Christey> See Andre"s comments, but I believe this is different than | CVE-1999-0769. Also consider CVE-1999-0768 and CVE-1999-0872 | (Vixie Cron buffer overflow via MAILTO), | View |
Page 312 of 20943, showing 5 records out of 104715 total, starting on record 1556, ending on 1560