CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3721 | CVE-2001-0915 | Candidate | Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition. | Modified (20050703) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:pmake-shell-format-string(7602) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement. | View |
3722 | CVE-2001-0916 | Candidate | Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition. | Modified (20050703) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:pmake-shell-bo(7603) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement. | View |
3996 | CVE-2001-1192 | Candidate | Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client. | Modified (20050703) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | Frech> XF:citrix-ica-gain-root(7697) | View |
3744 | CVE-2001-0938 | Candidate | Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp. | Modified (20050703) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:aspupload-upload-directory-traversal(7628) | XF:aspupload-directory-browsing-download(7629) | View |
3751 | CVE-2001-0945 | Candidate | Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line. | Modified (20050703) | ACCEPT(1) Green | MODIFY(2) Foat, Frech | NOOP(2) Cole, Wall | CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> Change the phrase "that contains a long line" to "that | contains a particular string". The buffer overflow does | not appear to be length dependeng, but string dependent. | Frech> XF:macos-outlook-long-message-bo(7648) | View |
Page 507 of 20943, showing 5 records out of 104715 total, starting on record 2531, ending on 2535