CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3141  CVE-2001-0320  Candidate  bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.  Proposed (20010404)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Bishop, Wall, Ziese  Frech> XF:php-nuke-elevate-privileges(6183) | CHANGE> [Bishop changed vote from REVIEWING to NOOP]  View
3142  CVE-2001-0321  Entry  opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.        View
3143  CVE-2001-0322  Candidate  MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.  Proposed (20010404)  ACCEPT(1) Frech | NOOP(2) Cole, Ziese | REJECT(1) LeBlanc | REVIEWING(2) Bishop, Wall  LeBlanc> I don"t believe that EX-CLIENT-DOS issues should be included | in CVE.  View
3144  CVE-2001-0323  Candidate  The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don"t Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.  Modified (20131008)  ACCEPT(2) Frech, Meunier | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop  Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> It seems obvious that if one sets the MTU to just one byte | above the size of a IP header (let"s say 21 bytes), data transmission | is not going to go anywhere fast, as the overhead will be 20 times the | payload... As I said for another candidate, ICMP messages should not | be acted upon without access control. I"m not sure that references to | UNIX should be kept. It seems that this should work with any OS. It | would be nasty if some OSes accepted an MTU of 20, as you could not | transmit any IP data.  View
3145  CVE-2001-0324  Candidate  Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.  Proposed (20010404)  MODIFY(1) Frech | NOOP(2) Cole, Ziese | RECAST(1) LeBlanc | REVIEWING(3) Baker, Bishop, Wall  LeBlanc> Sun"s Java specification does not provide for limits on the | number of sockets that can be opened. We didn"t write the spec, we just | implemented it. Aside from the issue of EX-CLIENT-DOS issues noted in my | comments on CVE-2001-0322, the vuln would need to be recast to show that | the actual problem lies in Java. If the description is recast to show | that the issue is in Sun"s Java specification, then please change my | vote to NOOP, as per the "don"t vote on issues with other vendors" rule. | Frech> XF:win-udp-dos(6070)  View

Page 629 of 20943, showing 5 records out of 104715 total, starting on record 3141, ending on 3145

Actions