CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4046  CVE-2001-1242  Candidate  Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4047  CVE-2001-1243  Candidate  Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View
4048  CVE-2001-1244  Candidate  Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4049  CVE-2001-1245  Candidate  Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall  CHANGE> [Green changed vote from REVIEWING to ACCEPT]  View
4050  CVE-2001-1246  Entry  PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.        View

Page 810 of 20943, showing 5 records out of 104715 total, starting on record 4046, ending on 4050

Actions