CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4072 | CVE-2001-1268 | Candidate | Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename. | Modified (20100521) | ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | Christey> MANDRAKE:MDKSA-2002:065 | Frech> XF:archive-extraction-directory-traversal(10224) | Christey> CONECTIVA:CLA-2002:538 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538 | HP:HPSBTL0209-068 | URL:http://online.securityfocus.com/advisories/4514 | REDHAT:RHSA-2002:096 | URL:http://www.redhat.com/support/errata/RHSA-2002-096.html | View |
4073 | CVE-2001-1269 | Candidate | Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the "/" (slash) character. | Modified (20100521) | ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | Christey> MANDRAKE:MDKSA-2002:065 | Frech> XF:archive-extraction-directory-traversal(10224) | Christey> CONECTIVA:CLA-2002:538 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538 | REDHAT:RHSA-2002:096 | URL:http://www.redhat.com/support/errata/RHSA-2002-096.html | View |
2404 | CVE-2000-0835 | Candidate | search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter. | Modified (20100115) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Collins, Wall | REJECT(2) Baker, Magdych | Magdych> Unless the beta product is in very widespread use, or the product is in | "perpetual beta" (e.g. ICQ), I would prefer not to include beta software. | Christey> XF:sambar-search-view-folder | Frech> XF:sambar-search-view-folder(5247) | Baker> Unless we change our CD:EX-BETA, we should reject this entry. Perhaps we need to address the issue of Beta software again, but the previous discussion was pretty thorough and I believe the editorial board was unanimous in excluding normal beta software. | Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar" | View |
4987 | CVE-2002-0596 | Candidate | WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message. | Modified (20100115) | ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | View | |
575 | CVE-1999-0593 | Candidate | The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. | Modified (20091029) | ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Northcutt | Wall> Still a denial of service. | Northcutt> May well be appropriate | Frech> XF:nt-shutdown-without-logon(1291) | View |
Page 434 of 20943, showing 5 records out of 104715 total, starting on record 2166, ending on 2170