CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2906 | CVE-2001-0085 | Entry | Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands. | View | |||
2907 | CVE-2001-0086 | Candidate | CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2908 | CVE-2001-0087 | Candidate | itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2909 | CVE-2001-0088 | Candidate | common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog. | Proposed (20010202) | ACCEPT(2) Baker, Frech | NOOP(3) Cole, Wall, Ziese | View | |
2910 | CVE-2001-0089 | Entry | Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability. | View |
Page 582 of 20943, showing 5 records out of 104715 total, starting on record 2906, ending on 2910