CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4161  CVE-2001-1357  Candidate  Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Alderson> Given the fact that there is limited information concerning | these "multiple" vulnerabilities mixed with the importance of time. It | appears that the information obtained so far is as sepcific as its going to | get. | Frech> XF:phpmychat-weak-input(9831)  View
4162  CVE-2001-1358  Candidate  Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Alderson> We should be ready to break this out into more seperate | Candidates should more information come to light on this. | Frech> XF:phpmychat-weak-input(9831)  View
4163  CVE-2001-1359  Entry  Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.        View
4164  CVE-2001-1360  Candidate  Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(2) Cox, Frech | NOOP(2) Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> I"m not sure how to vote on this, I did the research and read | the changlog and it appears that the issue you mention here has not | been fixed at all; merely documented as of sane version 1.0.5 | | Change description based on the information in the Sane tarball; note that | this affects all versions to date and is not fixed. | | ---cut--- | | - Security problems with pnm | If the pnm backend is installed and saned is used to allow users on | remote computers to scan on the local machine, pnm files can be read by | the remote user. This is limited to the files saned can access (usually | it"s running as user "sane"). All pnm files can be read if saned runs | as root which isn"t recommended anyway. The pnm backend is disabled | by default. If you want to use it, enable it with configure (see | configure --help for details). Be sure that only trusted users can | access the pnm backend over saned. | | ---cut--- | Frech> XF:sane-prm-read-files(9853)  View
4165  CVE-2001-1361  Candidate  Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:twig-mailto(9871)  View

Page 833 of 20943, showing 5 records out of 104715 total, starting on record 4161, ending on 4165

Actions