CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3306  CVE-2001-0489  Entry  Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.        View
3307  CVE-2001-0490  Candidate  Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Cole, Renaud, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:winamp-aip-bo(6479)  View
3308  CVE-2001-0491  Candidate  Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.  Modified (20010910-01)  ACCEPT(1) Williams | MODIFY(2) Baker, Frech | NOOP(4) Cole, Renaud, Wall, Ziese  Frech> XF:raidenftpd-dot-directory-traversal(6455) | Baker> Should probably modify description to say v2.1 prior to build 952, since the interim builds also had similar problems until build 952 resolved this.  View
3309  CVE-2001-0492  Candidate  Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.  Modified (20030619-02)  ACCEPT(4) Baker, Balinsky, Cole, Oliver | MODIFY(1) Frech | NOOP(4) Christey, Wall, Williams, Ziese  CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT] | Balinsky> Vendor acknowledged the problem in a personal communication. | Frech> XF:netcruiser-server-path-disclosure(6468) | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> Fix typo (accidental URL insertion) in XF reference  View
3310  CVE-2001-0493  Entry  Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.        View

Page 662 of 20943, showing 5 records out of 104715 total, starting on record 3306, ending on 3310

Actions