CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4847  CVE-2002-0455  Candidate  IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall  Green> INCLUSION RATIONALE IS A REASONABLE APROACH  View
4861  CVE-2002-0469  Candidate  Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA"s, which could allow local users to gain privileges.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4094  CVE-2001-1290  Candidate  admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.  Modified (20061107)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4494  CVE-2002-0100  Candidate  AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file.  Modified (20050710)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4498  CVE-2002-0104  Candidate  AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View

Page 869 of 20943, showing 5 records out of 104715 total, starting on record 4341, ending on 4345

Actions