CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4171  CVE-2001-1367  Entry  The checkAccess function in PHPSlice 0.1.4, and all other versions between 0.1.1 and 0.1.6, does not properly verify the administrative access level, which could allow remote attackers to gain privileges.        View
4172  CVE-2001-1368  Candidate  Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.  Proposed (20020611)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Alderson  Alderson> Although the CD:VAGUE is a great way to handle issues, what do we | gain from adding an entry to describe that which might have | already been described by any number of 4 others except as a | palceholder.  View
4173  CVE-2001-1369  Entry  Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields.        View
4174  CVE-2001-1370  Entry  prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.        View
4175  CVE-2001-1371  Entry  The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.        View

Page 835 of 20943, showing 5 records out of 104715 total, starting on record 4171, ending on 4175

Actions