CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3817  CVE-2001-1013  Candidate  Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.  Proposed (20020131)  ACCEPT(3) Cole, Frech, Green | MODIFY(2) Cox, Foat | REVIEWING(1) Wall  CHANGE> [Foat changed vote from REVIEWING to MODIFY] | Foat> This is only true if "indexes" are NOT enabled and the | "public_html" directory exists for the user. | Cox> The description says "Apache on Red Hat Linux". This issue | affects all versions of Apache that have UserDir enabled, not just | Linux or RHL. In Red Hat Linux we enable UserDir by default, but so | do other distributions.  View
4042  CVE-2001-1238  Candidate  Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REJECT(1) Baker | REVIEWING(1) Wall  Baker> I don"t think this is really a vulnerability. If I am not mistaken, | those are "services" which have to be managed by the services control | in windows 2K. This keeps users from killing things the system has | to have. I don"t think it is possible to kill another of other services | in this manner either. Try it on almost any W2K system, and there are any | number of services that you cannot kill from the process tab, rather you | must go to the services controller to stop the service. | I vote to reject this, as this is not a vulnerability, since you would have | to be administrator on the system to change one of these services to a trojan | version anyway.  View
4129  CVE-2001-1325  Candidate  Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View
4047  CVE-2001-1243  Candidate  Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View
4113  CVE-2001-1309  Candidate  Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View

Page 971 of 20943, showing 5 records out of 104715 total, starting on record 4851, ending on 4855

Actions