CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3371 | CVE-2001-0558 | Entry | T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0). | View | |||
3372 | CVE-2001-0559 | Entry | crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error. | View | |||
3373 | CVE-2001-0560 | Entry | Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters). | View | |||
3374 | CVE-2001-0561 | Candidate | Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a ".." (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi. | Modified (20050509) | ACCEPT(3) Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Bishop | Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description. | View |
3375 | CVE-2001-0562 | Candidate | a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters. | Proposed (20010727) | ACCEPT(3) Cole, Frech, Ziese | NOOP(4) Bishop, Christey, Foat, Wall | Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1 | 5&t=000008 | Statement of fix is ambiguous: A major security flaw in the scripts | has now been fixed. For obvious reasons the details of the flaw will | not be posted here. | Site lists their product as A1-Stats, not A1Stats as in description. | CHANGE> [Bishop changed vote from REVIEWING to NOOP] | Christey> The URL recommended by Andre is *probably* addressing this | problem, but it"s not quite certain. There is insufficient | detail to determine if the vendor has truly acknowledged the | problem. I have an email to a1stats@gadnet.com to see | if I can confirm. | | This is affected by CD:SF-EXEC since multiple executables in the same | package are affected (a1disp.cgi, a1disp2.cgi, a1disp4.cgi, and | a1disp3.cgi). | Christey> Received confirmation via email, 2/26/2002. | View |
Page 675 of 20943, showing 5 records out of 104715 total, starting on record 3371, ending on 3375