CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3876  CVE-2001-1072  Entry  Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.        View
3877  CVE-2001-1073  Candidate  Webridge PX Application Suite allows remote attackers to obtain sensitive information via a malformed request that generates a server error message, which includes full pathname or internal IP address information in the variables (1) APPL_PHYSICAL_PATH, (2) PATH_TRANSLATED, and (3) LOCAL_ADDR.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View
3878  CVE-2001-1074  Entry  Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.        View
3879  CVE-2001-1075  Entry  poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker"s IP address to be injected into the maillog log file.        View
3880  CVE-2001-1076  Candidate  Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.  Modified (20061101)  ACCEPT(2) Frech, Green | MODIFY(1) Dik | NOOP(3) Armstrong, Cole, Foat | REVIEWING(1) Wall  Dik> Sun bug: 4477380 | Description errors: CFIME -> CFTIME | Don"t understand "SOR" environment variable. This must | presumably be TZ  View

Page 776 of 20943, showing 5 records out of 104715 total, starting on record 3876, ending on 3880

Actions