CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5147  CVE-2002-0757  Candidate  (1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin to accept arbitrary username/session ID combinations.  Proposed (20020726)  ACCEPT(2) Baker, Cole | NOOP(5) Armstrong, Christey, Cox, Foat, Wall  Christey> This *might* be vendor acknowledgement: | URL:http://www.geocrawler.com/lists/3/SourceForge/12082/0/8595354/ | | However, the person who"s credited by the vendor found *TWO* | authentication-related vulnerabilities at about the same time, | and the vendor is clearly fixing "a" vulnerability. So, which | issue did the vendor fix? Which issue is the vendor | acknowledging - CVE-2002-0757 or CVE-2002-0756?  View
2401  CVE-2000-0832  Candidate  Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.  Modified (20010910-01)  ACCEPT(2) Baker, Collins | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Wall  Frech> XF:htgrep-cgi-view-files(5476) | Collins> http://www.iam.unibe.ch/~scg/Src/Doc/ | Christey> The change log for htgrep acknowledges the problem, but it | says that the qry tag is also affected. CD:SF-LOC says that | multiple problems of the same type in the same version should | be combined, so this candidate should get a "soft recast" | and qry should be added to the description.  View
2395  CVE-2000-0826  Candidate  Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request.  Proposed (20001018)  ACCEPT(2) Baker, Collins | NOOP(3) Armstrong, Cole, Wall    View
2396  CVE-2000-0827  Candidate  Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.  Proposed (20001018)  ACCEPT(2) Baker, Collins | NOOP(3) Armstrong, Cole, Wall    View
2397  CVE-2000-0828  Candidate  Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.  Proposed (20001018)  ACCEPT(2) Baker, Collins | NOOP(3) Armstrong, Cole, Wall    View

Page 780 of 20943, showing 5 records out of 104715 total, starting on record 3896, ending on 3900

Actions