CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4073  CVE-2001-1269  Candidate  Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the "/" (slash) character.  Modified (20100521)  ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | Christey> MANDRAKE:MDKSA-2002:065 | Frech> XF:archive-extraction-directory-traversal(10224) | Christey> CONECTIVA:CLA-2002:538 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538 | REDHAT:RHSA-2002:096 | URL:http://www.redhat.com/support/errata/RHSA-2002-096.html  View
4570  CVE-2002-0177  Candidate  Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client.  Modified (20050510)  ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall  Christey> CALDERA:CSSA-2002-020.0 | Christey> Change "allows" to "allow," and add "as exploited through the | client_login function" (to facilitate matching). | REDHAT:RHSA-2002:063 | Frech> XF:icecast-clientlogin-bo(8741)  View
5752  CVE-2002-1368  Candidate  Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.  Modified (20071220)  ACCEPT(3) Cole, Cox, Green | NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:001  View
5767  CVE-2002-1383  Candidate  Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.  Modified (20071220)  ACCEPT(3) Cole, Cox, Green | NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:001  View
2205  CVE-2000-0629  Candidate  The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.  Proposed (20000803)  ACCEPT(3) Cole, Dik, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall  Frech> XF:sunjava-webadmin-bbs(5135) | Christey> Need to create/update | Dik> (through internal confirmation)  View

Page 960 of 20943, showing 5 records out of 104715 total, starting on record 4796, ending on 4800

Actions