CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3614 | CVE-2001-0808 | Candidate | gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter. | Proposed (20011122) | ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(3) Armstrong, Foat, Wall | Bishop> If the SPECIFIC nature of the problem is determined to be both, I would | accept two separate candidates. But in the absence of this information, | I favor accepting it now rather than waiting for details. We can always | revisit it later. | View |
3529 | CVE-2001-0721 | Candidate | Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request. | Proposed (20011122) | ACCEPT(3) Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | RECAST(3) Armstrong, Baker, Bishop | Bishop> I agree that these should be split, as the abstraction says. | Frech> XF:win-upnp-dos(7428) | Baker> SPLIT | Armstrong> SPLIT | Christey> Consider adding BID:3499 | Christey> CIAC:M-015 | URL:http://www.ciac.org/ciac/bulletins/m-015.shtml | XF:win-upnp-dos(7428) | URL:http://www.iss.net/security_center/static/7428.php | BID:3499 | URL:http://www.securityfocus.com/bid/3499 | View |
5622 | CVE-2002-1238 | Candidate | Peter Sandvik"s Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/. | Modified (20050610) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Balinsky, Cox, Wall | Balinsky> Software site http://linuxstuffs.cjb.net/ is down, and no information is available on the software. Cannot confirm. | View |
5597 | CVE-2002-1213 | Candidate | Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters. | Modified (20050615) | ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall | Balinsky> Software download sites dead. Cannot confirm. | View |
5520 | CVE-2002-1133 | Candidate | Encoded directory traversal vulnerability in Dino"s web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "" (%5c) characters. | Proposed (20030317) | ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall | Balinsky> No confirmation available. Software apparently no longer available. | View |
Page 363 of 20943, showing 5 records out of 104715 total, starting on record 1811, ending on 1815