CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4000 | CVE-2001-1196 | Candidate | Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a ".." (dot dot) in the argument. | Proposed (20020315) | ACCEPT(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Green> SINCE ROOT PRIVILEGES ARE REQUIRED TO USE THE TOOL, WHAT FURTHER | ESCALATION OF PRIVILEGE CAN OBTAINED? | View |
3793 | CVE-2001-0988 | Candidate | Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information. | Proposed (20020131) | ACCEPT(2) Cole, Frech | MODIFY(1) Green | NOOP(3) Armstrong, Foat, Wall | Green> SEEMS TO BE CONTRADICTING INFORMATION IN THE MESSAGES AT BUGTRAQ | View |
5396 | CVE-2002-1008 | Candidate | Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil" HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request. | Proposed (20020830) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> PUBLISHER"S WEBSITE INDICATES SECURITY FIXES | View |
5338 | CVE-2002-0950 | Candidate | Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered. | Proposed (20020830) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> Publisher has released update and a new version. | Unfortunately the homepage is in Japanese, making a | determination of whether or not the presenting problem has been | addressed rather speculative. | View |
6875 | CVE-2003-0046 | Candidate | AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials. | Modified (20080207) | ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | Green> PRODUCT ANNOUNCEMENT CONTAINS VENDOR ACKNOWLEDGEMENT | View |
Page 42 of 20943, showing 5 records out of 104715 total, starting on record 206, ending on 210