CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3817 | CVE-2001-1013 | Candidate | Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server. | Proposed (20020131) | ACCEPT(3) Cole, Frech, Green | MODIFY(2) Cox, Foat | REVIEWING(1) Wall | CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> This is only true if "indexes" are NOT enabled and the | "public_html" directory exists for the user. | Cox> The description says "Apache on Red Hat Linux". This issue | affects all versions of Apache that have UserDir enabled, not just | Linux or RHL. In Red Hat Linux we enable UserDir by default, but so | do other distributions. | View |
3751 | CVE-2001-0945 | Candidate | Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line. | Modified (20050703) | ACCEPT(1) Green | MODIFY(2) Foat, Frech | NOOP(2) Cole, Wall | CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> Change the phrase "that contains a long line" to "that | contains a particular string". The buffer overflow does | not appear to be length dependeng, but string dependent. | Frech> XF:macos-outlook-long-message-bo(7648) | View |
1109 | CVE-1999-1129 | Candidate | Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag. | Proposed (20010912) | ACCEPT(2) Foat, Frech | NOOP(2) Cole, Wall | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
1215 | CVE-1999-1235 | Candidate | Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user"s index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link. | Proposed (20010912) | ACCEPT(4) Cole, Foat, Frech, Wall | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
1267 | CVE-1999-1287 | Candidate | Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface. | Proposed (20010912) | ACCEPT(4) Armstrong, Cole, Frech, Stracener | NOOP(2) Foat, Wall | CHANGE> [Foat changed vote from ACCEPT to NOOP] | View |
Page 350 of 20943, showing 5 records out of 104715 total, starting on record 1746, ending on 1750