CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3516 | CVE-2001-0708 | Candidate | Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string. | Proposed (20010829) | ACCEPT(5) Baker, Cole, Frech, Stracener, Ziese | NOOP(2) Foat, Wall | Stracener> CONFIRM: http://www.denicomp.com/rexecdnt.htm | View |
3517 | CVE-2001-0709 | Candidate | Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode. | Proposed (20010829) | ACCEPT(3) Foat, Frech, Ziese | NOOP(3) Armstrong, Bishop, Cole | REVIEWING(1) Wall | CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
3518 | CVE-2001-0710 | Entry | NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool. | View | |||
3519 | CVE-2001-0711 | Candidate | Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string. | Modified (20020228-01) | ACCEPT(5) Baker, Balinsky, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:cisco-ios-modify-snmp(6169) | Christey> Change desc to say that the ILMI allows viewing/modification | of certain objects, which *then* leads to a DoS. | | Thanks to Andre Frech for noticing this. | | CERT-VN:VU#976280 | View |
3520 | CVE-2001-0712 | Candidate | The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc. | Proposed (20011012) | ACCEPT(2) Baker, Cole | NOOP(1) Armstrong | REJECT(2) Foat, Frech | REVIEWING(1) Wall | Baker> I would argue that a browser executing a script when it shouldn"t is still a vulnerability. If it is supposed to be a non-scriptable file type, and that fails, resulting in a script being executed without the user"s knowledge, then it is a problem, and thus should be included as a vulnerability. I vote this should be accepted, and if Microsoft acknowledges this in their follow up, then you have vendor acknowledgement of the problem as well. | Foat> The candidate does not meet the criteria for a vulnerability or | exposure, even though it describes an unexpected behavior. | View |
Page 704 of 20943, showing 5 records out of 104715 total, starting on record 3516, ending on 3520