CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3626  CVE-2001-0820  Candidate  Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.  Proposed (20011122)  ACCEPT(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall    View
3627  CVE-2001-0821  Candidate  The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.  Proposed (20011122)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Frech | NOOP(2) Foat, Wall    View
3628  CVE-2001-0822  Entry  FPF kernel module 1.0 allows a remote attacker to cause a denial of service via fragmented packets.        View
3629  CVE-2001-0823  Entry  The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).        View
3630  CVE-2001-0824  Candidate  Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.  Proposed (20011122)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall  Frech> XF:java-servlet-crosssite-scripting(6793) | This issue is associated with multiple operating | environments. | Christey> CERT-VN:VU#560659 | URL:http://www.kb.cert.org/vuls/id/560659 | MISC:http://www.kb.cert.org/vuls/id/JARL-4YZKLU  View

Page 726 of 20943, showing 5 records out of 104715 total, starting on record 3626, ending on 3630

Actions