CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3311  CVE-2001-0494  Entry  Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.        View
3312  CVE-2001-0495  Entry  Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.        View
3313  CVE-2001-0496  Candidate  kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.  Modified (20010910-01)  ACCEPT(4) Baker, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Renaud, Wall | REVIEWING(1) Christey  Williams> kdesu is part of kdelibs package. since entire kdelibs package must be upgraded, and since kdelibs (rather than kdesu) is referenced in most advisories related to this issue, we might want to reference kdelibs in this CAN. | Frech> XF:kdelibs-kdesu-insecure-tmpfile(6856) | Christey> Agree with Ken Williams. The CVE descriptions in general | should capture all "reasonable" keywords under which | someone may know the vulnerability. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> It"s possible that this is the same vulnerability as CVE-2001-0178, | but the description is written so differently from the others, that | it"s hard to be sure. In addition, Mandrake released a separate | advisory for CVE-2001-0178. | BID:2669 addresses CVE-2001-0178.  View
3314  CVE-2001-0497  Entry  dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.        View
3315  CVE-2001-0498  Candidate  Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.  Proposed (20010727)  ACCEPT(5) Armstrong, Cole, Prosser, Stracener, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:oracle-listener-offsettodata-dos(6713) | CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_dos.pdf | CVE-2001-0498 possible dupe of CVE-2001-0515, which is already | assigned to oracle-listener-offsettodata-dos(6713) | Prosser> Discover of issue (NAI) indicates that Oracle produced a patch for this issue. Oracle patch site is restricted, but taking NAI"s word as verification. | Christey> Consider adding BID:2940  View

Page 663 of 20943, showing 5 records out of 104715 total, starting on record 3311, ending on 3315

Actions