CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3221  CVE-2001-0403  Candidate  /opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.  Proposed (20010524)  ACCEPT(2) Baker, Frech | NOOP(3) Cole, Wall, Ziese    View
3222  CVE-2001-0404  Candidate  Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:jswdk-directory-traversal(6312)  View
3223  CVE-2001-0405  Entry  ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.        View
3224  CVE-2001-0406  Candidate  Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.  Modified (20050509)  ACCEPT(5) Baker, Cole, Prosser, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:samba-tmpfile-symlink(6396) | Christey> note to self: double-check related submissions to ensure that | all references are complete | Christey> ADDREF RHSA-2001:044 (per Mark Cox of Red Hat) | Christey> Add "2.0.8 and earlier" to description; problem was fixed in | 2 different versions, and initial 2.0.8 fixes were incorrect. | BUGTRAQ:20010508 Samba 2.0.9 released - 2.0.8 did NOT fix the hole | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0061.html | IMMUNIX:IMNX-2001-70-019-01 | BUGTRAQ:20010525 TSLSA-2001-0006: Samba | URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0242.html | CALDERA:CSSA-2001-018.0 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-018.0.txt  View
3225  CVE-2001-0407  Entry  Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).        View

Page 645 of 20943, showing 5 records out of 104715 total, starting on record 3221, ending on 3225

Actions