CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3176  CVE-2001-0355  Candidate  Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.  Proposed (20010524)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Oliver, Wall, Ziese  Frech> XF:novell-groupwise-bypass-policies(6089)  View
3177  CVE-2001-0357  Candidate  FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.  Modified (20060526)  ACCEPT(2) Baker, Frech | NOOP(6) Bishop, Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Williams  Baker> http://www.securityfocus.com/archive/1/168177 | http://www.securityfocus.com/archive/1/168292 | http://www.securityfocus.com/archive/1/168366 | http://www.securityfocus.com/archive/1/168345 | http://www.securityfocus.com/archive/1/168302 | http://www.securityfocus.com/archive/1/168360 | http://www.securityfocus.com/archive/1/168633 | | I think from the discussion on the Bugtraq list, there is sufficient verfication that this | is a real problem, and well-known. There are a couple of work arounds | described in the posts, so this should be accepted. | Christey> Fix typo: "paramaters" | Christey> Fix typo: "paramater" | Christey> The following references discuss this problem and/or later | variants of it, up to version 1.9. | MISC:http://www.softwolves.pp.se/misc/formmail_hall_of_shame | MISC:http://www.monkeys.com/anti-spam/formmail-advisory.pdf | MISC:http://www.scriptarchive.com/readme/formmail.html  View
3178  CVE-2001-0358  Candidate  Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View
3179  CVE-2001-0359  Candidate  Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View
3180  CVE-2001-0360  Candidate  Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.  Proposed (20010524)  ACCEPT(2) Cole, Frech | NOOP(3) Oliver, Wall, Ziese    View

Page 636 of 20943, showing 5 records out of 104715 total, starting on record 3176, ending on 3180

Actions