CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2771  CVE-2000-1204  Candidate  Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.  Proposed (20020830)  ACCEPT(5) Armstrong, Baker, Cole, Cox, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:apache-modvhostalias-source-disclosure(11088)  View
2772  CVE-2000-1205  Candidate  Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.  Modified (20070926)  ACCEPT(7) Armstrong, Baker, Cole, Cox, Foat, Green, Wall | MODIFY(1) Frech  Frech> XF:apache-printenv-xss(10938)  View
2773  CVE-2000-1206  Candidate  Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:apache-virtualhosting-obtain-files(11139)  View
2774  CVE-2000-1207  Candidate  userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:usermode-userhelper-bypass-security(11089)  View
2775  CVE-2000-1208  Candidate  Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Frech, Green | NOOP(2) Foat, Wall    View

Page 555 of 20943, showing 5 records out of 104715 total, starting on record 2771, ending on 2775

Actions