CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1369 | CVE-1999-1389 | Candidate | US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:3com-netserver-filter-bypass(7330) | View |
24100 | CVE-2007-0743 | Candidate | URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process. | Assigned (20070205) | None (candidate not yet proposed) | View | |
16648 | CVE-2006-0544 | Candidate | urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters. | Assigned (20060204) | None (candidate not yet proposed) | View | |
4408 | CVE-2002-0014 | Entry | URL-handling code in Pine 4.43 and earlier allows remote attackers to execute arbitrary commands via a URL enclosed in single quotes and containing shell metacharacters (&). | View | |||
895 | CVE-1999-0915 | Entry | URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | View |
Page 808 of 20943, showing 5 records out of 104715 total, starting on record 4036, ending on 4040