CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4636  CVE-2002-0244  Candidate  Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.  Modified (20050528)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:atheos-dot-directory-traversal(8108)  View
4637  CVE-2002-0245  Candidate  Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server"s version name in the HTTP error message.  Proposed (20020502)  ACCEPT(4) Armstrong, Cole, Frech, Wall | NOOP(2) Cox, Foat    View
4638  CVE-2002-0246  Entry  Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.        View
4639  CVE-2002-0247  Candidate  Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.  Proposed (20020502)  ACCEPT(4) Armstrong, Cole, Frech, Wall | NOOP(2) Cox, Foat  Frech> CONFIRM:http://www.debian.org/security/2002/dsa-108  View
4640  CVE-2002-0248  Candidate  wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.  Proposed (20020502)  ACCEPT(3) Armstrong, Cole, Frech | NOOP(3) Cox, Foat, Wall    View

Page 928 of 20943, showing 5 records out of 104715 total, starting on record 4636, ending on 4640

Actions