CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3370  CVE-2001-0557  Candidate  T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a ".." (dot dot) attack which is URL encoded (%2e%2e).  Modified (20050509)  ACCEPT(2) Frech, Ziese | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Bishop    View
3374  CVE-2001-0561  Candidate  Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a ".." (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.  Modified (20050509)  ACCEPT(3) Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Bishop  Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description.  View
3121  CVE-2001-0300  Candidate  oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.  Modified (20050509)  NOOP(3) Cole, Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop  Frech> Validity threshold is not met by the references cited. Would | be willing to reassess and change vote if more information is | forthcoming.  View
3170  CVE-2001-0349  Candidate  Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.  Modified (20050509)  ACCEPT(7) Armstrong, Balinsky, Cole, Foat, Stracener, Wall, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey  CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT] | Balinsky> Need to decide whether this and 2001-350 one or two vuls, but it is definitely valid. | Frech> XF:win2k-telnet-pipe-privileges(6664) | Christey> CIAC:L-092 | URL:http://www.ciac.org/ciac/bulletins/l-092.shtml | Christey> Consider adding BID:2849 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CERT-VN:VU#587587 | URL:http://www.kb.cert.org/vuls/id/587587 | BID:2849 | Microsoft identifies two separate vulnerabilities that are extremely | similar, but the security bulletin states that "The two | vulnerabilities differ primarily in the way they exploit the | underlying problem regarding named pipe creation." So, it may be | necessary to merge CVE-2001-0350 with CVE-2001-0349. | | If one issue is because of predictable names, and another | issue is because pipe ownership isn"t properly verified, then | these could stay SPLIT, and the descriptions should be | modified accordingly.  View
3171  CVE-2001-0350  Candidate  Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.  Modified (20050509)  ACCEPT(5) Armstrong, Balinsky, Cole, Foat, Ziese | MODIFY(1) Frech | RECAST(1) Stracener | REVIEWING(2) Christey, Wall  Wall> Perhaps merge 0349 and 0350 unless there is a bigger difference. | Stracener> Merge this with 0349. | Frech> XF:win2k-telnet-pipe-privileges(6664) | Christey> CIAC:L-092 | URL:http://www.ciac.org/ciac/bulletins/l-092.shtml | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CERT-VN:VU#587587 | URL:http://www.kb.cert.org/vuls/id/587587 | BID:2849 | Microsoft identifies two separate vulnerabilities that are extremely | similar, but the security bulletin states that "The two | vulnerabilities differ primarily in the way they exploit the | underlying problem regarding named pipe creation." So, it may be | necessary to merge CVE-2001-0350 with CVE-2001-0349. | | If one issue is because of predictable names, and another | issue is because pipe ownership isn"t properly verified, then | these could stay SPLIT, and the descriptions should be | modified accordingly.  View

Page 530 of 20943, showing 5 records out of 104715 total, starting on record 2646, ending on 2650

Actions