CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4146  CVE-2001-1342  Entry  Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.        View
4147  CVE-2001-1343  Candidate  ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall  Green> As this vulnerability requires the exploiter to have an authenticated administrative login, is it an oxymoron?  View
4148  CVE-2001-1344  Candidate  WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4149  CVE-2001-1345  Entry  bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.        View
4150  CVE-2001-1346  Candidate  Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:arcserveit-inetd-tmpfile-symlink(10006) | XF:arcserveit-asagent-tmpfile-symlink(10007)  View

Page 830 of 20943, showing 5 records out of 104715 total, starting on record 4146, ending on 4150

Actions