CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3626 | CVE-2001-0820 | Candidate | Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c. | Proposed (20011122) | ACCEPT(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall | View | |
3627 | CVE-2001-0821 | Candidate | The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt. | Proposed (20011122) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Frech | NOOP(2) Foat, Wall | View | |
3628 | CVE-2001-0822 | Entry | FPF kernel module 1.0 allows a remote attacker to cause a denial of service via fragmented packets. | View | |||
3629 | CVE-2001-0823 | Entry | The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR). | View | |||
3630 | CVE-2001-0824 | Candidate | Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page. | Proposed (20011122) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall | Frech> XF:java-servlet-crosssite-scripting(6793) | This issue is associated with multiple operating | environments. | Christey> CERT-VN:VU#560659 | URL:http://www.kb.cert.org/vuls/id/560659 | MISC:http://www.kb.cert.org/vuls/id/JARL-4YZKLU | View |
Page 726 of 20943, showing 5 records out of 104715 total, starting on record 3626, ending on 3630