CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4636 | CVE-2002-0244 | Candidate | Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir. | Modified (20050528) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:atheos-dot-directory-traversal(8108) | View |
4637 | CVE-2002-0245 | Candidate | Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server"s version name in the HTTP error message. | Proposed (20020502) | ACCEPT(4) Armstrong, Cole, Frech, Wall | NOOP(2) Cox, Foat | View | |
4638 | CVE-2002-0246 | Entry | Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint. | View | |||
4639 | CVE-2002-0247 | Candidate | Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges. | Proposed (20020502) | ACCEPT(4) Armstrong, Cole, Frech, Wall | NOOP(2) Cox, Foat | Frech> CONFIRM:http://www.debian.org/security/2002/dsa-108 | View |
4640 | CVE-2002-0248 | Candidate | wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file. | Proposed (20020502) | ACCEPT(3) Armstrong, Cole, Frech | NOOP(3) Cox, Foat, Wall | View |
Page 928 of 20943, showing 5 records out of 104715 total, starting on record 4636, ending on 4640