CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3516  CVE-2001-0708  Candidate  Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string.  Proposed (20010829)  ACCEPT(5) Baker, Cole, Frech, Stracener, Ziese | NOOP(2) Foat, Wall  Stracener> CONFIRM: http://www.denicomp.com/rexecdnt.htm  View
3517  CVE-2001-0709  Candidate  Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.  Proposed (20010829)  ACCEPT(3) Foat, Frech, Ziese | NOOP(3) Armstrong, Bishop, Cole | REVIEWING(1) Wall  CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | CHANGE> [Foat changed vote from NOOP to ACCEPT]  View
3518  CVE-2001-0710  Entry  NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.        View
3519  CVE-2001-0711  Candidate  Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.  Modified (20020228-01)  ACCEPT(5) Baker, Balinsky, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:cisco-ios-modify-snmp(6169) | Christey> Change desc to say that the ILMI allows viewing/modification | of certain objects, which *then* leads to a DoS. | | Thanks to Andre Frech for noticing this. | | CERT-VN:VU#976280  View
3520  CVE-2001-0712  Candidate  The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.  Proposed (20011012)  ACCEPT(2) Baker, Cole | NOOP(1) Armstrong | REJECT(2) Foat, Frech | REVIEWING(1) Wall  Baker> I would argue that a browser executing a script when it shouldn"t is still a vulnerability. If it is supposed to be a non-scriptable file type, and that fails, resulting in a script being executed without the user"s knowledge, then it is a problem, and thus should be included as a vulnerability. I vote this should be accepted, and if Microsoft acknowledges this in their follow up, then you have vendor acknowledgement of the problem as well. | Foat> The candidate does not meet the criteria for a vulnerability or | exposure, even though it describes an unexpected behavior.  View

Page 704 of 20943, showing 5 records out of 104715 total, starting on record 3516, ending on 3520

Actions