CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4491 | CVE-2002-0097 | Entry | Geeklog 1.3 allows remote attackers to hijack user accounts, including the administrator account, by modifying the UID of a user"s permanent cookie to the target account. | View | |||
4492 | CVE-2002-0098 | Entry | Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner. | View | |||
4493 | CVE-2002-0099 | Candidate | Buffer overflow in Michael Lamont Savant Web Server 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP request to the cgi-bin directory in which the CGI program name contains a large number of . (dot) characters. | Modified (20020911-01) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey | Christey> Should CVE-2002-0099 and/or CVE-2001-0433 be MERGED with | CVE-2000-0641? All describe slightly different overflows | that, perhaps, should be merged according to CD:SF-LOC. | It depends on which versions are affected, which would require | some vendor acknowledgement or consultation. | | A vague changelog for version 3.1 at | http://sourceforge.net/project/shownotes.php?release_id=75333 says | "security fixes" but it"s not clear *which* security fixes | were made. | | The description for CVE-2000-0641 is slightly incorrect. The | exploit is clearly due to a large number of headers, not | arguments to the GET request itself. So, CVE-2000-0641 | clearly overlaps with CVE-2001-0433. | | The exploit for CVE-2001-0433 also doesn"t really have | anything to do with a "cgi-test.pl" program (which isn"t in | the distribution). The discloser simply used that as an | example program of a long request. | Christey> Modify description so that overflow is described as being | part of the CGI module (so it appears). | | Also, Tamer Sahin confirmed via email (9/11/02) that the | problem was explicitly exhibited using a large number of | . (dot) characters. | View |
4494 | CVE-2002-0100 | Candidate | AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file. | Modified (20050710) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | View | |
4495 | CVE-2002-0101 | Candidate | Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released. | Proposed (20020315) | ACCEPT(4) Foat, Frech, Green, Ziese | NOOP(1) Cole | REVIEWING(1) Wall | Ziese> would seem appropriate as a CVE entry. | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
Page 899 of 20943, showing 5 records out of 104715 total, starting on record 4491, ending on 4495