CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3585  CVE-2001-0778  Candidate  OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).  Modified (20020225-01)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View
3589  CVE-2001-0782  Candidate  KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.  Proposed (20011012)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View
3714  CVE-2001-0908  Candidate  CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).  Proposed (20020131)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View
3717  CVE-2001-0911  Candidate  PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View
3730  CVE-2001-0924  Candidate  Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View

Page 695 of 20943, showing 5 records out of 104715 total, starting on record 3471, ending on 3475

Actions