CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2891  CVE-2001-0070  Candidate  Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2897  CVE-2001-0076  Candidate  register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2907  CVE-2001-0086  Candidate  CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2908  CVE-2001-0087  Candidate  itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2918  CVE-2001-0097  Candidate  The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> Version is listed as 3.61 (see | http://support.infinite.com/kb/648.asp) | Also, vendor seems to have issued a verification (see above | document): | - - WebMail: Fix for an exception error triggered by a POST request | with | an extremely long garbage URL. (v3.61.08)  View

Page 692 of 20943, showing 5 records out of 104715 total, starting on record 3456, ending on 3460

Actions