CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3251  CVE-2001-0433  Candidate  Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Christey  Frech> XF:savant-get-bo(4901) | Christey> Should CVE-2002-0099 and/or CVE-2001-0433 be MERGED with | CVE-2000-0641? All describe slightly different overflows | that, perhaps, should be merged according to CD:SF-LOC. | It depends on which versions are affected, which would require | some vendor acknowledgement or consultation. | | A vague changelog for version 3.1 at | http://sourceforge.net/project/shownotes.php?release_id=75333 says | "security fixes" but it"s not clear *which* security fixes | were made. | | The description for CVE-2000-0641 is slightly incorrect. The | exploit is clearly due to a large number of headers, not | arguments to the GET request itself. So, CVE-2000-0641 | clearly overlaps with CVE-2001-0433. | | The exploit for CVE-2001-0433 also doesn"t really have | anything to do with a "cgi-test.pl" program (which isn"t in | the distribution). The discloser simply used that as an | example program of a long request.  View
3252  CVE-2001-0434  Entry  The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.        View
3253  CVE-2001-0435  Candidate  The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese  Frech> XF:nai-pgp-split-keys(6341)  View
3254  CVE-2001-0436  Candidate  dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.  Interim (20010911)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:dcforum-az-expr(6392)  View
3255  CVE-2001-0437  Candidate  upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.  Interim (20010911)  ACCEPT(3) Baker, Cole, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:dcforum-az-file-upload(6393)  View

Page 651 of 20943, showing 5 records out of 104715 total, starting on record 3251, ending on 3255

Actions