CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3456 | CVE-2001-0647 | Candidate | Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version. | Modified (20071219) | ACCEPT(2) Foat, Williams | MODIFY(1) Frech | NOOP(4) Christey, Cole, Stracener, Wall | Frech> XF:orange-http-echo-dos(6164) | Christey> Need to clean up BID, add other Bugtraq ref. | View |
3880 | CVE-2001-1076 | Candidate | Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable. | Modified (20061101) | ACCEPT(2) Frech, Green | MODIFY(1) Dik | NOOP(3) Armstrong, Cole, Foat | REVIEWING(1) Wall | Dik> Sun bug: 4477380 | Description errors: CFIME -> CFTIME | Don"t understand "SOR" environment variable. This must | presumably be TZ | View |
4503 | CVE-2002-0109 | Candidate | Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query. | Proposed (20020315) | ACCEPT(2) Frech, Green | MODIFY(1) Foat | NOOP(2) Cole, Wall | Foat> Our testing showed that this vulnerabiltiy did not apply to BEFSR41 | routers. | View |
3791 | CVE-2001-0986 | Candidate | SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(2) Cole, Foat | REVIEWING(1) Wall | Frech> http://www.kb.cert.org/vuls/id/914859 | View |
3804 | CVE-2001-0999 | Candidate | Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(2) Cole, Foat | REVIEWING(1) Wall | View |
Page 853 of 20943, showing 5 records out of 104715 total, starting on record 4261, ending on 4265