CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4146 | CVE-2001-1342 | Entry | Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer. | View | |||
4147 | CVE-2001-1343 | Candidate | ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter. | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> As this vulnerability requires the exploiter to have an authenticated administrative login, is it an oxymoron? | View |
4148 | CVE-2001-1344 | Candidate | WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot). | Proposed (20020502) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
4149 | CVE-2001-1345 | Entry | bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program. | View | |||
4150 | CVE-2001-1346 | Candidate | Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:arcserveit-inetd-tmpfile-symlink(10006) | XF:arcserveit-asagent-tmpfile-symlink(10007) | View |
Page 830 of 20943, showing 5 records out of 104715 total, starting on record 4146, ending on 4150