CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3038 | CVE-2001-0217 | Candidate | Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter. | Modified (20060609) | ACCEPT(1) Baker | MODIFY(2) Frech, Lawler | NOOP(2) Cole, Ziese | Lawler> Combine with CVE-2001-0216 | Frech> XF:webpals-library-cgi-url(6102) | View |
418 | CVE-1999-0419 | Candidate | When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. | Modified (20000105-01) | ACCEPT(1) Baker | MODIFY(2) Frech, LeBlanc | REVIEWING(1) Christey | Frech> XF:smtp-4xx-error-dos | LeBlanc> - if we can find a KB or something that shows that this wasn"t just | user error, I"d vote ACCEPT. | Christey> David Lemson, Microsoft SMTP Service Program Manager, | posted a followup that said "We have confirmed this as a | problem..." | http://marc.theaimsgroup.com/?l=bugtraq&m=92171608127206&w=2 | View |
1848 | CVE-2000-0270 | Candidate | The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack. | Proposed (20000426) | ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall | Christey> ADDREF XF:emacs-tempfile-creation | Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | Frech> XF:emacs-tempfile-creation | Levy> Change BID reference to BID 1126 | View |
1849 | CVE-2000-0271 | Candidate | read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords. | Proposed (20000426) | ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall | Christey> Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | ADDREF XF:emacs-password-history | Frech> XF:emacs-password-history | Levy> Change BID reference to BID 1127 | View |
2266 | CVE-2000-0690 | Candidate | Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter. | Proposed (20000921) | ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall | Levy> Reference: BID 1645 | Christey> BID:1645 | URL:http://www.securityfocus.com/bid/1645 | Frech> XF:auction-weaver-execute-commands(6175) | View |
Page 636 of 20943, showing 5 records out of 104715 total, starting on record 3176, ending on 3180