CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3611  CVE-2001-0805  Entry  Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the pg parameter.        View
3612  CVE-2001-0806  Entry  Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user"s desktop folder via insecure default permissions for the Desktop when it is created in some languages.        View
3613  CVE-2001-0807  Candidate  Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client"s hard drive via a SCRIPT tag with a SRC value that points to the text file.  Modified (20020226-01)  ACCEPT(3) Baker, Cole, Prosser | MODIFY(1) Frech | NOOP(3) Armstrong, Bishop, Foat | REVIEWING(2) Christey, Wall  Frech> XF:ie-local-file-disclosure(6688) | Prosser> Legacy product, users should have updated. | Courtesy of Microsoft Security Response Center <secure@microsoft.com>: | | IE 5 is no longer supported - so unless this repro"s on 5.01 or 5.5, we wouldn"t consider doing anything for this. | Christey> ADDREF BID:2836 | URL:http://www.securityfocus.com/bid/2836 | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3614  CVE-2001-0808  Candidate  gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.  Proposed (20011122)  ACCEPT(4) Baker, Bishop, Cole, Frech | NOOP(3) Armstrong, Foat, Wall  Bishop> If the SPECIFIC nature of the problem is determined to be both, I would | accept two separate candidates. But in the absence of this information, | I favor accepting it now rather than waiting for details. We can always | revisit it later.  View
3615  CVE-2001-0809  Candidate  Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.  Modified (20090302)  ACCEPT(4) Armstrong, Bishop, Cole, Foat | NOOP(1) Wall | REJECT(1) Frech  Frech> See XF:samba-tmpfile-symlink(6396). | Discovery and advisory are two months apart, and no other Samba | issues seem to exist around that timespan.  View

Page 723 of 20943, showing 5 records out of 104715 total, starting on record 3611, ending on 3615

Actions