CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4331  CVE-2001-1531  Candidate  Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename.  Assigned (20050714)  None (candidate not yet proposed)    View
4332  CVE-2001-1532  Candidate  WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.  Assigned (20050714)  None (candidate not yet proposed)    View
4333  CVE-2001-1533  Candidate  ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.  Assigned (20050714)  None (candidate not yet proposed)    View
4334  CVE-2001-1534  Candidate  mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID"s using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID"s and bypass authentication when these session ID"s are used for authentication.  Assigned (20050714)  None (candidate not yet proposed)    View
4335  CVE-2001-1535  Candidate  Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID"s from cookies and gain unauthorized access via a brute force attack.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 867 of 20943, showing 5 records out of 104715 total, starting on record 4331, ending on 4335

Actions