CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1369  CVE-1999-1389  Candidate  US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:3com-netserver-filter-bypass(7330)  View
24100  CVE-2007-0743  Candidate  URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process.  Assigned (20070205)  None (candidate not yet proposed)    View
16648  CVE-2006-0544  Candidate  urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.  Assigned (20060204)  None (candidate not yet proposed)    View
4408  CVE-2002-0014  Entry  URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&).        View
895  CVE-1999-0915  Entry  URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.        View

Page 808 of 20943, showing 5 records out of 104715 total, starting on record 4036, ending on 4040

Actions