CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4130  CVE-2001-1326  Candidate  Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:eudora-msviewer-execute-attachment(6635)  View
4150  CVE-2001-1346  Candidate  Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:arcserveit-inetd-tmpfile-symlink(10006) | XF:arcserveit-asagent-tmpfile-symlink(10007)  View
4084  CVE-2001-1280  Candidate  POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:imail-account-brute-force(7272)  View
4087  CVE-2001-1283  Candidate  The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:imail-dot-mailbox-dos(7277)  View
4079  CVE-2001-1275  Candidate  MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Christey  Christey> CALDERA:CSSA-2001-006.0 specifically says they"re not | vulnerable to this issue. So, do we remove the reference | (because they aren"t affected by this problem), or do we | keep the reference because it specifically mentions this | issue? | | Need to review the other advisories; they don"t necessarily | have the details to know whether they"re addressing this | problem or not (the overflow mentioned in these refs is | covered by CVE-2001-1274). MANDRAKE:MDKSA-2001:014 | clearly identifies this issue. | | FREEBSD:FreeBSD-SA-01:16 discussed "remote vulerabilities" | (plural), which *could* include this issue, but it is not | absolutely certain. REDHAT:RHSA-2001:003 refers to | "information protection issues," but that"s not clear enough | either. | | Thanks to John Segura of secureinfo.com for noticing this | issue. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mysql-show-grants-password(9996)  View

Page 839 of 20943, showing 5 records out of 104715 total, starting on record 4191, ending on 4195

Actions