CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4216  CVE-2001-1413  Candidate  Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.  Assigned (20041018)  None (candidate not yet proposed)    View
4217  CVE-2001-1414  Candidate  The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.  Assigned (20050208)  None (candidate not yet proposed)    View
4218  CVE-2001-1415  Candidate  vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes.  Assigned (20050318)  None (candidate not yet proposed)    View
4219  CVE-2001-1416  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.  Assigned (20050320)  None (candidate not yet proposed)    View
4220  CVE-2001-1417  Candidate  AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 844 of 20943, showing 5 records out of 104715 total, starting on record 4216, ending on 4220

Actions