CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3816  CVE-2001-1012  Candidate  Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.  Modified (20020817-01)  ACCEPT(2) Frech, Green | NOOP(4) Christey, Cole, Foat, Wall  Christey> Typo: "toa"  View
3817  CVE-2001-1013  Candidate  Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.  Proposed (20020131)  ACCEPT(3) Cole, Frech, Green | MODIFY(2) Cox, Foat | REVIEWING(1) Wall  CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> This is only true if "indexes" are NOT enabled and the | "public_html" directory exists for the user. | Cox> The description says "Apache on Red Hat Linux". This issue | affects all versions of Apache that have UserDir enabled, not just | Linux or RHL. In Red Hat Linux we enable UserDir by default, but so | do other distributions.  View
3818  CVE-2001-1014  Candidate  eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3819  CVE-2001-1015  Candidate  Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:snes9x-rom-bo(7295)  View
3820  CVE-2001-1016  Entry  PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID"s are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."        View

Page 764 of 20943, showing 5 records out of 104715 total, starting on record 3816, ending on 3820

Actions