CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4072 | CVE-2001-1268 | Candidate | Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename. | Modified (20100521) | ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | Christey> MANDRAKE:MDKSA-2002:065 | Frech> XF:archive-extraction-directory-traversal(10224) | Christey> CONECTIVA:CLA-2002:538 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538 | HP:HPSBTL0209-068 | URL:http://online.securityfocus.com/advisories/4514 | REDHAT:RHSA-2002:096 | URL:http://www.redhat.com/support/errata/RHSA-2002-096.html | View |
4891 | CVE-2002-0499 | Candidate | The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories. | Proposed (20020611) | ACCEPT(3) Cole, Foat, Frech | NOOP(3) Armstrong, Cox, Wall | REVIEWING(1) Christey | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | CHANGE> [Cox changed vote from ACCEPT to NOOP] | Christey> Need to investigate this more... is it the responsibility | of the kernel to address this, or the application | programmer? | View |
4631 | CVE-2002-0239 | Candidate | Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument. | Modified (20050703) | ACCEPT(4) Armstrong, Cole, Cox, Frech | NOOP(2) Foat, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | View |
5783 | CVE-2002-1399 | Candidate | Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2). | Proposed (20030317) | ACCEPT(2) Baker, Cox | NOOP(2) Cole, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | View |
4061 | CVE-2001-1257 | Candidate | Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email. | Proposed (20020502) | ACCEPT(4) Cole, Cox, Frech, Green | NOOP(2) Foat, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | View |
Page 355 of 20943, showing 5 records out of 104715 total, starting on record 1771, ending on 1775