CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2891 | CVE-2001-0070 | Candidate | Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2897 | CVE-2001-0076 | Candidate | register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2907 | CVE-2001-0086 | Candidate | CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2908 | CVE-2001-0087 | Candidate | itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | View | |
2918 | CVE-2001-0097 | Candidate | The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request. | Proposed (20010202) | ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> Version is listed as 3.61 (see | http://support.infinite.com/kb/648.asp) | Also, vendor seems to have issued a verification (see above | document): | - - WebMail: Fix for an exception error triggered by a POST request | with | an extremely long garbage URL. (v3.61.08) | View |
Page 692 of 20943, showing 5 records out of 104715 total, starting on record 3456, ending on 3460