CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2906  CVE-2001-0085  Entry  Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.        View
2907  CVE-2001-0086  Candidate  CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2908  CVE-2001-0087  Candidate  itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2909  CVE-2001-0088  Candidate  common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.  Proposed (20010202)  ACCEPT(2) Baker, Frech | NOOP(3) Cole, Wall, Ziese    View
2910  CVE-2001-0089  Entry  Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.        View

Page 582 of 20943, showing 5 records out of 104715 total, starting on record 2906, ending on 2910

Actions