CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2897  CVE-2001-0076  Candidate  register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2900  CVE-2001-0079  Candidate  Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.  Proposed (20010202)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:stm-log-files-symlink(6126) | BID-2158  View
2903  CVE-2001-0082  Candidate  Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.  Proposed (20010202)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:fw1-bypass-rules(6000) | BID-2143  View
2905  CVE-2001-0084  Candidate  GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.  Proposed (20010202)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Christey, Cole, Prosser, Wall, Ziese  Frech> XF:gtk-module-execute-code(5832) | Christey> XF:gtk-module-execute-code | URL:http://xforce.iss.net/static/5832.php | Christey> TURBO:TLSA2001026 | URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000440.html  View
2907  CVE-2001-0086  Candidate  CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View

Page 320 of 20943, showing 5 records out of 104715 total, starting on record 1596, ending on 1600

Actions