CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3030  CVE-2001-0209  Candidate  Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description.  Proposed (20010309)  ACCEPT(1) Frech | NOOP(2) Lawler, Ziese    View
3052  CVE-2001-0231  Candidate  Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter.  Modified (20050509)  ACCEPT(1) Frech | NOOP(2) Lawler, Ziese    View
1266  CVE-1999-1286  Candidate  addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.  Modified (20060623)  ACCEPT(1) Frech | NOOP(3) Christey, Cole, Foat  Christey> CHANGE DESC: "via a symlink attack on the printers temporary file." | Add 5.3 as another affected version. | | MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX | SGI:19961203-02-PX may solve this problem, but the advisory is so | vague that it is uncertain whether this was fixed or not. addnetpr is | not specifically named in the advisory, which names netprint, which is | not specified in the original Bugtraq post. In addition, the date on | the advisory is one day earlier than that of the Bugtraq post, though | that could be a difference in time zones. It seems plausible that the | problem had already been patched (the researcher did say "There *was* | [a] race condition") so maybe SGI released this advisory after the | problem was publicized. | | ADDREF BID:330 | URL:http://www.securityfocus.com/bid/330 | | Note: this is a dupe of CVE-1999-1410, but CVE-1999-1410 will | be rejected in favor of CVE-1999-1286.  View
3019  CVE-2001-0198  Candidate  Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.  Modified (20130403)  ACCEPT(1) Frech | NOOP(3) Christey, Lawler, Ziese  Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar"  View
5430  CVE-2002-1042  Candidate  Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via .. (dot-dot backslash) sequences in the NS-query-pat parameter.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall    View

Page 678 of 20943, showing 5 records out of 104715 total, starting on record 3386, ending on 3390

Actions