CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4331 | CVE-2001-1531 | Candidate | Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4332 | CVE-2001-1532 | Candidate | WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4333 | CVE-2001-1533 | Candidate | ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4334 | CVE-2001-1534 | Candidate | mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID"s using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID"s and bypass authentication when these session ID"s are used for authentication. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4335 | CVE-2001-1535 | Candidate | Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID"s from cookies and gain unauthorized access via a brute force attack. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 867 of 20943, showing 5 records out of 104715 total, starting on record 4331, ending on 4335