CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3817 | CVE-2001-1013 | Candidate | Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server. | Proposed (20020131) | ACCEPT(3) Cole, Frech, Green | MODIFY(2) Cox, Foat | REVIEWING(1) Wall | CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> This is only true if "indexes" are NOT enabled and the | "public_html" directory exists for the user. | Cox> The description says "Apache on Red Hat Linux". This issue | affects all versions of Apache that have UserDir enabled, not just | Linux or RHL. In Red Hat Linux we enable UserDir by default, but so | do other distributions. | View |
4042 | CVE-2001-1238 | Candidate | Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager. | Proposed (20020502) | ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REJECT(1) Baker | REVIEWING(1) Wall | Baker> I don"t think this is really a vulnerability. If I am not mistaken, | those are "services" which have to be managed by the services control | in windows 2K. This keeps users from killing things the system has | to have. I don"t think it is possible to kill another of other services | in this manner either. Try it on almost any W2K system, and there are any | number of services that you cannot kill from the process tab, rather you | must go to the services controller to stop the service. | I vote to reject this, as this is not a vulnerability, since you would have | to be administrator on the system to change one of these services to a trojan | version anyway. | View |
4129 | CVE-2001-1325 | Candidate | Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH). | Proposed (20020502) | ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REVIEWING(1) Wall | View | |
4047 | CVE-2001-1243 | Candidate | Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject. | Proposed (20020502) | ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REVIEWING(1) Wall | View | |
4113 | CVE-2001-1309 | Candidate | Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | Proposed (20020502) | ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall | View |
Page 971 of 20943, showing 5 records out of 104715 total, starting on record 4851, ending on 4855