CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3816 | CVE-2001-1012 | Candidate | Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/. | Modified (20020817-01) | ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall | Christey> Typo: "toa" | View |
3817 | CVE-2001-1013 | Candidate | Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server. | Proposed (20020131) | ACCEPT(3) Cole, Frech, Green | MODIFY(2) Cox, Foat | REVIEWING(1) Wall | CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> This is only true if "indexes" are NOT enabled and the | "public_html" directory exists for the user. | Cox> The description says "Apache on Red Hat Linux". This issue | affects all versions of Apache that have UserDir enabled, not just | Linux or RHL. In Red Hat Linux we enable UserDir by default, but so | do other distributions. | View |
3818 | CVE-2001-1014 | Candidate | eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
3819 | CVE-2001-1015 | Candidate | Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument. | Proposed (20020131) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:snes9x-rom-bo(7295) | View |
3820 | CVE-2001-1016 | Entry | PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID"s are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability." | View |
Page 764 of 20943, showing 5 records out of 104715 total, starting on record 3816, ending on 3820