CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3696  CVE-2001-0890  Candidate  Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.  Proposed (20020726)  ACCEPT(5) Armstrong, Baker, Cole, Cox, Wall | NOOP(1) Foat    View
3697  CVE-2001-0891  Entry  Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.        View
3698  CVE-2001-0892  Candidate  Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.  Proposed (20020131)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:httpd-bypass-permissions(7541) | Christey> CONECTIVA:CLA-2003:777  View
3699  CVE-2001-0893  Candidate  Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.  Modified (20050703)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:httpd-bypass-permissions(7541)  View
3700  CVE-2001-0894  Entry  Vulnerability in Postfix SMTP server before 20010228-pl07, when configured to email the postmaster when SMTP errors cause the session to terminate, allows remote attackers to cause a denial of service (memory exhaustion) by generating a large number of SMTP errors, which forces the SMTP session log to grow too large.        View

Page 740 of 20943, showing 5 records out of 104715 total, starting on record 3696, ending on 3700

Actions