CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3886  CVE-2001-1082  Candidate  Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20020131)  ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Christey | NOOP(2) Foat, Wall | REJECT(1) Frech  Frech> Reference no longer exists, and has no title for cross | reference. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> Dead reference; will reconsider revote if valid reference | presented. | Christey> MISC:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html  View
3887  CVE-2001-1083  Entry  Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or (backward slash).        View
3888  CVE-2001-1084  Entry  Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.        View
3889  CVE-2001-1085  Entry  Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.        View
3890  CVE-2001-1086  Candidate  XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.  Proposed (20020315)  ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall    View

Page 778 of 20943, showing 5 records out of 104715 total, starting on record 3886, ending on 3890

Actions