CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3176 | CVE-2001-0355 | Candidate | Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies. | Proposed (20010524) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Oliver, Wall, Ziese | Frech> XF:novell-groupwise-bypass-policies(6089) | View |
3177 | CVE-2001-0357 | Candidate | FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters. | Modified (20060526) | ACCEPT(2) Baker, Frech | NOOP(6) Bishop, Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Williams | Baker> http://www.securityfocus.com/archive/1/168177 | http://www.securityfocus.com/archive/1/168292 | http://www.securityfocus.com/archive/1/168366 | http://www.securityfocus.com/archive/1/168345 | http://www.securityfocus.com/archive/1/168302 | http://www.securityfocus.com/archive/1/168360 | http://www.securityfocus.com/archive/1/168633 | | I think from the discussion on the Bugtraq list, there is sufficient verfication that this | is a real problem, and well-known. There are a couple of work arounds | described in the posts, so this should be accepted. | Christey> Fix typo: "paramaters" | Christey> Fix typo: "paramater" | Christey> The following references discuss this problem and/or later | variants of it, up to version 1.9. | MISC:http://www.softwolves.pp.se/misc/formmail_hall_of_shame | MISC:http://www.monkeys.com/anti-spam/formmail-advisory.pdf | MISC:http://www.scriptarchive.com/readme/formmail.html | View |
3178 | CVE-2001-0358 | Candidate | Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file. | Proposed (20010524) | ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese | View | |
3179 | CVE-2001-0359 | Candidate | Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command. | Proposed (20010524) | ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese | View | |
3180 | CVE-2001-0360 | Candidate | Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter. | Proposed (20010524) | ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese | View |
Page 636 of 20943, showing 5 records out of 104715 total, starting on record 3176, ending on 3180