CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4081  CVE-2001-1277  Entry  makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.        View
4082  CVE-2001-1278  Candidate  Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Foat | REJECT(3) Christey, Cox, Frech  Christey> Agreed; dupe of CVE-2001-1227  View
4083  CVE-2001-1279  Entry  Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.        View
4084  CVE-2001-1280  Candidate  POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:imail-account-brute-force(7272)  View
4085  CVE-2001-1281  Candidate  Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:imail-change-user-info(7273)  View

Page 817 of 20943, showing 5 records out of 104715 total, starting on record 4081, ending on 4085

Actions