CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3066  CVE-2001-0245  Entry  Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.        View
3067  CVE-2001-0246  Candidate  Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.  Proposed (20010524)  ACCEPT(5) Baker, Cole, Magdych, Wall, Williams | MODIFY(1) Frech | NOOP(2) Renaud, Ziese | REVIEWING(1) Christey  Christey> See comments for CVE-2001-0332; may need to be merged because | of CD:SF-LOC. | Frech> XF:ie-frame-verification-variant(6748)  View
3068  CVE-2001-0247  Candidate  Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.  Modified (20010910-01)  ACCEPT(5) Baker, Cole, Oliver, Renaud, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:ftp-glob-expansion(6332) | Christey> ADDREF SGI:20010802-01-P | Christey> COMPAQ:SSRT-547 | URL:http://archives.neohapsis.com/archives/tru64/2002-q3/0017.html  View
3069  CVE-2001-0248  Candidate  Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.  Interim (20010911)  ACCEPT(5) Baker, Cole, Prosser, Renaud, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:ftp-glob-expansion(6332) | Prosser> HPSBUX0107-162. Probably should change description to add the | HP-UX 10.01, 10.10, 10.20, 10.24 (VVOS), 11.04 (VVOS) and 11.11 | versions of the operating system as well. Patches for all systems | referenced in the advisory.  View
3070  CVE-2001-0249  Candidate  Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.  Interim (20010911)  ACCEPT(5) Baker, Cole, Dik, Renaud, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:ftp-glob-expansion(6332) | Dik> sun bug: 4436988 | Dik> sun bug: 4436988  View

Page 614 of 20943, showing 5 records out of 104715 total, starting on record 3066, ending on 3070

Actions