CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3370 | CVE-2001-0557 | Candidate | T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a ".." (dot dot) attack which is URL encoded (%2e%2e). | Modified (20050509) | ACCEPT(2) Frech, Ziese | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Bishop | View | |
3374 | CVE-2001-0561 | Candidate | Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a ".." (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi. | Modified (20050509) | ACCEPT(3) Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Bishop | Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description. | View |
3121 | CVE-2001-0300 | Candidate | oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack. | Modified (20050509) | NOOP(3) Cole, Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop | Frech> Validity threshold is not met by the references cited. Would | be willing to reassess and change vote if more information is | forthcoming. | View |
3170 | CVE-2001-0349 | Candidate | Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability. | Modified (20050509) | ACCEPT(7) Armstrong, Balinsky, Cole, Foat, Stracener, Wall, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey | CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT] | Balinsky> Need to decide whether this and 2001-350 one or two vuls, but it is definitely valid. | Frech> XF:win2k-telnet-pipe-privileges(6664) | Christey> CIAC:L-092 | URL:http://www.ciac.org/ciac/bulletins/l-092.shtml | Christey> Consider adding BID:2849 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CERT-VN:VU#587587 | URL:http://www.kb.cert.org/vuls/id/587587 | BID:2849 | Microsoft identifies two separate vulnerabilities that are extremely | similar, but the security bulletin states that "The two | vulnerabilities differ primarily in the way they exploit the | underlying problem regarding named pipe creation." So, it may be | necessary to merge CVE-2001-0350 with CVE-2001-0349. | | If one issue is because of predictable names, and another | issue is because pipe ownership isn"t properly verified, then | these could stay SPLIT, and the descriptions should be | modified accordingly. | View |
3171 | CVE-2001-0350 | Candidate | Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability. | Modified (20050509) | ACCEPT(5) Armstrong, Balinsky, Cole, Foat, Ziese | MODIFY(1) Frech | RECAST(1) Stracener | REVIEWING(2) Christey, Wall | Wall> Perhaps merge 0349 and 0350 unless there is a bigger difference. | Stracener> Merge this with 0349. | Frech> XF:win2k-telnet-pipe-privileges(6664) | Christey> CIAC:L-092 | URL:http://www.ciac.org/ciac/bulletins/l-092.shtml | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CERT-VN:VU#587587 | URL:http://www.kb.cert.org/vuls/id/587587 | BID:2849 | Microsoft identifies two separate vulnerabilities that are extremely | similar, but the security bulletin states that "The two | vulnerabilities differ primarily in the way they exploit the | underlying problem regarding named pipe creation." So, it may be | necessary to merge CVE-2001-0350 with CVE-2001-0349. | | If one issue is because of predictable names, and another | issue is because pipe ownership isn"t properly verified, then | these could stay SPLIT, and the descriptions should be | modified accordingly. | View |
Page 530 of 20943, showing 5 records out of 104715 total, starting on record 2646, ending on 2650