CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3614  CVE-2001-0808  Candidate  gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.  Proposed (20011122)  ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(3) Armstrong, Foat, Wall  Bishop> If the SPECIFIC nature of the problem is determined to be both, I would | accept two separate candidates. But in the absence of this information, | I favor accepting it now rather than waiting for details. We can always | revisit it later.  View
3529  CVE-2001-0721  Candidate  Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.  Proposed (20011122)  ACCEPT(3) Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | RECAST(3) Armstrong, Baker, Bishop  Bishop> I agree that these should be split, as the abstraction says. | Frech> XF:win-upnp-dos(7428) | Baker> SPLIT | Armstrong> SPLIT | Christey> Consider adding BID:3499 | Christey> CIAC:M-015 | URL:http://www.ciac.org/ciac/bulletins/m-015.shtml | XF:win-upnp-dos(7428) | URL:http://www.iss.net/security_center/static/7428.php | BID:3499 | URL:http://www.securityfocus.com/bid/3499  View
5622  CVE-2002-1238  Candidate  Peter Sandvik"s Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.  Modified (20050610)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Balinsky, Cox, Wall  Balinsky> Software site http://linuxstuffs.cjb.net/ is down, and no information is available on the software. Cannot confirm.  View
5597  CVE-2002-1213  Candidate  Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.  Modified (20050615)  ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall  Balinsky> Software download sites dead. Cannot confirm.  View
5520  CVE-2002-1133  Candidate  Encoded directory traversal vulnerability in Dino"s web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "" (%5c) characters.  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall  Balinsky> No confirmation available. Software apparently no longer available.  View

Page 363 of 20943, showing 5 records out of 104715 total, starting on record 1811, ending on 1815

Actions