CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4011  CVE-2001-1207  Candidate  Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.  Proposed (20020315)  ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall  Frech> Corrected link to DayDream BBS ChangeLog: | http://daydream.iwn.fi/history.html  View
4012  CVE-2001-1208  Candidate  Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.  Proposed (20020315)  MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese  Frech> XF:daydream-bbs-format-string(9120)  View
4013  CVE-2001-1209  Candidate  Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey  Christey> INCLUSION: The author of the zml.cgi program says that the vulnerable | version is not his, and that zml.cgi does not take a file parameter. | If this is an adaptation of that zml.cgi program, and the adaptation | is not generally available, then it should not be included in CVE. | Almost all of the hits on Google for "zml.cgi" are references to the | reported vulnerability, and a search for "zml" doesn"t turn up any | obvious web pages, so it cannot be determined if there is another | product that happens to use a script named zml.cgi.  View
4014  CVE-2001-1210  Candidate  Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.  Modified (20050703)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Ziese    View
4015  CVE-2001-1211  Candidate  Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View

Page 803 of 20943, showing 5 records out of 104715 total, starting on record 4011, ending on 4015

Actions