CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3676  CVE-2001-0870  Candidate  HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.  Proposed (20020131)  NOOP(4) Armstrong, Cole, Foat, Wall    View
3677  CVE-2001-0871  Candidate  Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.  Modified (20050510)  NOOP(4) Armstrong, Cole, Foat, Wall    View
3678  CVE-2001-0872  Entry  OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.        View
3679  CVE-2001-0873  Entry  uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.        View
3680  CVE-2001-0874  Entry  Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes information from a frame in the client"s domain to a frame in the web site"s domain, a variant of the "Frame Domain Verification" vulnerability.        View

Page 736 of 20943, showing 5 records out of 104715 total, starting on record 3676, ending on 3680

Actions