CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3251 | CVE-2001-0433 | Candidate | Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Christey | Frech> XF:savant-get-bo(4901) | Christey> Should CVE-2002-0099 and/or CVE-2001-0433 be MERGED with | CVE-2000-0641? All describe slightly different overflows | that, perhaps, should be merged according to CD:SF-LOC. | It depends on which versions are affected, which would require | some vendor acknowledgement or consultation. | | A vague changelog for version 3.1 at | http://sourceforge.net/project/shownotes.php?release_id=75333 says | "security fixes" but it"s not clear *which* security fixes | were made. | | The description for CVE-2000-0641 is slightly incorrect. The | exploit is clearly due to a large number of headers, not | arguments to the GET request itself. So, CVE-2000-0641 | clearly overlaps with CVE-2001-0433. | | The exploit for CVE-2001-0433 also doesn"t really have | anything to do with a "cgi-test.pl" program (which isn"t in | the distribution). The discloser simply used that as an | example program of a long request. | View |
3252 | CVE-2001-0434 | Entry | The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service. | View | |||
3253 | CVE-2001-0435 | Candidate | The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese | Frech> XF:nai-pgp-split-keys(6341) | View |
3254 | CVE-2001-0436 | Candidate | dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. | Interim (20010911) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:dcforum-az-expr(6392) | View |
3255 | CVE-2001-0437 | Candidate | upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file. | Interim (20010911) | ACCEPT(3) Baker, Cole, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:dcforum-az-file-upload(6393) | View |
Page 651 of 20943, showing 5 records out of 104715 total, starting on record 3251, ending on 3255