CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3085  CVE-2001-0264  Candidate  Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.  Proposed (20010524)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Oliver, Wall | REVIEWING(1) Ziese  Frech> XF:bpftp-obtain-credentials(6330)  View
3117  CVE-2001-0296  Candidate  Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.  Proposed (20010404)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Wall, Ziese | RECAST(1) Prosser | REVIEWING(1) Bishop  Frech> XF:wftpd-pro-cwd-bo(6184) | Prosser> See http://www.mail-archive.com/bugtraq@securityfocus.com/msg05671.html for additional info on this one. It looks like Can-2001-0296 may be a continuation of CVE 1999-0950. Appears from ref that this problem has been in every version since the 2.40 problem reported Oct 1999 (CVE 1999-0950). Just managed to change the code so it requires more characters to overflow the buffer. I haven"t tested this, but just from the available documentation, these problems look like a continuation of the early one.  View
3703  CVE-2001-0897  Candidate  Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.  Proposed (20020131)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Armstrong, Foat, Wall  Frech> XF:ultimatebb-cookie-gain-privileges(6142) | Is this a variant of the following references: | BugTraq Mailing List, Wed Feb 21 2001 13:19:16 Ultimate Bulletin | Board, http://online.securityfocus.com/archive/1/164583 | BugTraq Mailing List, Wed Feb 21 2001 17:59:13 Re: Ultimate Bulletin | Board, http://online.securityfocus.com/archive/1/164716  View
3141  CVE-2001-0320  Candidate  bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.  Proposed (20010404)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Bishop, Wall, Ziese  Frech> XF:php-nuke-elevate-privileges(6183) | CHANGE> [Bishop changed vote from REVIEWING to NOOP]  View
2952  CVE-2001-0131  Candidate  htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.  Modified (20010430-01)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Magdych, Wall  Frech> XF:linux-apache-symlink(5926) | Christey> XF:linux-apache-symlink | URL:http://xforce.iss.net/static/5926.php | Christey> http://archives.neohapsis.com/archives/vendor/2001-q1/0019.html | Christey> This item may have been re-introduced into the Apache source | code sometime during 2002; CVE-2002-1233 has been created for | that version, which affects Apache 1.3.27 and other versions. | Christey> As a further clarification, CVE-2002-1233 is *only* for the | Debian-specific regression error. | Christey> DEBIAN:DSA-195 | URL:http://www.debian.org/security/2002/dsa-195  View

Page 772 of 20943, showing 5 records out of 104715 total, starting on record 3856, ending on 3860

Actions