CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1031 | CVE-1999-1051 | Candidate | Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey | Frech> XF:formhandler-cgi-reply-message(7782) | Christey> I view one of these as a configuration issue: FormHandler.cgi | *could* be configured to limit hard-coded pathnames to a single | directory which, while being an information leak, would still be | "reasonably secure." But by default, it"s just not configured that | way. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are. | View |
66567 | CVE-2013-6620 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20131105) | None (candidate not yet proposed) | View | |
1287 | CVE-1999-1307 | Candidate | Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges. | Proposed (20010912) | ACCEPT(4) Armstrong, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF;novell-unixware-urestore-root(7211) | View |
66823 | CVE-2013-6876 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20131126) | None (candidate not yet proposed) | View | |
1543 | CVE-1999-1563 | Candidate | Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:icmp-redirect(285) | View |
Page 562 of 20943, showing 5 records out of 104715 total, starting on record 2806, ending on 2810