CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5744 | CVE-2002-1360 | Candidate | Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite. | Modified (20090302) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Cox | REVIEWING(1) Wall | Frech> XF:ssh-transport-null-string-bo(10871) | View |
2667 | CVE-2000-1100 | Candidate | The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:postaci-webmail-reveal-passwords(5612) | View |
2670 | CVE-2000-1103 | Candidate | rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:rcvtty-elevate-privileges(5587) | View |
2677 | CVE-2000-1110 | Candidate | document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program. | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:ibm-netdata-reveal-path(5599) | View |
2681 | CVE-2000-1114 | Candidate | Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20". | Proposed (20001219) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:ewave-jsp-source-read(5562) | View |
Page 620 of 20943, showing 5 records out of 104715 total, starting on record 3096, ending on 3100