CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4011 | CVE-2001-1207 | Candidate | Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA. | Proposed (20020315) | ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall | Frech> Corrected link to DayDream BBS ChangeLog: | http://daydream.iwn.fi/history.html | View |
4012 | CVE-2001-1208 | Candidate | Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code. | Proposed (20020315) | MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Frech> XF:daydream-bbs-format-string(9120) | View |
4013 | CVE-2001-1209 | Candidate | Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey | Christey> INCLUSION: The author of the zml.cgi program says that the vulnerable | version is not his, and that zml.cgi does not take a file parameter. | If this is an adaptation of that zml.cgi program, and the adaptation | is not generally available, then it should not be included in CVE. | Almost all of the hits on Google for "zml.cgi" are references to the | reported vulnerability, and a search for "zml" doesn"t turn up any | obvious web pages, so it cannot be determined if there is another | product that happens to use a script named zml.cgi. | View |
4014 | CVE-2001-1210 | Candidate | Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings. | Modified (20050703) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Ziese | View | |
4015 | CVE-2001-1211 | Candidate | Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View |
Page 803 of 20943, showing 5 records out of 104715 total, starting on record 4011, ending on 4015