CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3721  CVE-2001-0915  Candidate  Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition.  Modified (20050703)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:pmake-shell-format-string(7602) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement.  View
3722  CVE-2001-0916  Candidate  Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition.  Modified (20050703)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:pmake-shell-bo(7603) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement.  View
3996  CVE-2001-1192  Candidate  Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client.  Modified (20050703)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese  Frech> XF:citrix-ica-gain-root(7697)  View
3744  CVE-2001-0938  Candidate  Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp.  Modified (20050703)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:aspupload-upload-directory-traversal(7628) | XF:aspupload-directory-browsing-download(7629)  View
3751  CVE-2001-0945  Candidate  Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.  Modified (20050703)  ACCEPT(1) Green | MODIFY(2) Foat, Frech | NOOP(2) Cole, Wall  CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> Change the phrase "that contains a long line" to "that | contains a particular string". The buffer overflow does | not appear to be length dependeng, but string dependent. | Frech> XF:macos-outlook-long-message-bo(7648)  View

Page 507 of 20943, showing 5 records out of 104715 total, starting on record 2531, ending on 2535

Actions