CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3121 | CVE-2001-0300 | Candidate | oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack. | Modified (20050509) | NOOP(3) Cole, Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop | Frech> Validity threshold is not met by the references cited. Would | be willing to reassess and change vote if more information is | forthcoming. | View |
3122 | CVE-2001-0301 | Entry | Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings. | View | |||
3123 | CVE-2001-0302 | Candidate | Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL. | Proposed (20010404) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:pi3web-isapi-bo(6113) | Christey> CONFIRM:http://sourceforge.net/tracker/index.php?func=detail&aid=410354&group_id=17753&atid=117753 | View |
3124 | CVE-2001-0303 | Candidate | tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file. | Proposed (20010404) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:pi3web-reveal-path(6114) | Christey> This issue was rediscovered a year later, in version 2.0.0. | Since it"s a default configuration problem, it is likely that | the vendor did not fix it. | BUGTRAQ:20020310 Pi3Web/2.0.0 File-Disclosure/Path Disclosure vuln | URL:http://online.securityfocus.com/archive/1/260734 | BID:4261 | XF:pi3web-error-disclosure(8428) | View |
3125 | CVE-2001-0304 | Candidate | Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in a URL request. | Proposed (20010404) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:resin-directory-traversal(6118) | View |
Page 625 of 20943, showing 5 records out of 104715 total, starting on record 3121, ending on 3125