CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3093  CVE-2001-0272  Candidate  Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.  Proposed (20010404)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:sendtemp-pl-read-files(6104) | Amaya, not Anaya  View
3736  CVE-2001-0930  Candidate  Sendpage.pl allows remote attackers to execute arbitrary commands via a message containing shell metacharacters.  Modified (20050702)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:sendpage-message-command-execution(7609)  View
3521  CVE-2001-0713  Candidate  Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.  Modified (20050702)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:sendmail-setregid-gain-privileges(7192) | Christey> Consider adding BID:3377 | Christey> BID:3377 | URL:http://www.securityfocus.com/bid/3377  View
3522  CVE-2001-0714  Candidate  Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.  Modified (20050704)  ACCEPT(6) Armstrong, Baker, Cole, Foat, Prosser, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:sendmail-queue-dos(7190) | Christey> ADDREF SGI:20011101-01-I | Christey> CALDERA:CSSA-2001-034.0 | URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-034.0.txt | BID:3378 | URL:http://www.securityfocus.com/bid/3378 | CIAC:M-020 | URL:http://ciac.llnl.gov/ciac/bulletins/m-020.shtml  View
3523  CVE-2001-0715  Candidate  Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.  Modified (20050704)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:sendmail-debug-gain-information(7191) | Christey> ADDREF SGI:20011101-01-I | Christey> CIAC:M-020 | URL:http://ciac.llnl.gov/ciac/bulletins/m-020.shtml | HP:HPSBUX0201-179 | URL:http://www.securityfocus.com/advisories/3794 | BID:3898 | URL:http://www.securityfocus.com/bid/3898 | It *might* be that HP:HPSBUX0201-179 addresses this, but the | advisory is too vague to be certain. | URL:http://www.securityfocus.com/advisories/3794  View

Page 90 of 20943, showing 5 records out of 104715 total, starting on record 446, ending on 450

Actions