CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3886 | CVE-2001-1082 | Candidate | Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack. | Proposed (20020131) | ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Christey | NOOP(2) Foat, Wall | REJECT(1) Frech | Frech> Reference no longer exists, and has no title for cross | reference. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> Dead reference; will reconsider revote if valid reference | presented. | Christey> MISC:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html | View |
3887 | CVE-2001-1083 | Entry | Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or (backward slash). | View | |||
3888 | CVE-2001-1084 | Entry | Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message. | View | |||
3889 | CVE-2001-1085 | Entry | Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | View | |||
3890 | CVE-2001-1086 | Candidate | XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack. | Proposed (20020315) | ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall | View |
Page 778 of 20943, showing 5 records out of 104715 total, starting on record 3886, ending on 3890