CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3756  CVE-2001-0950  Candidate  ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.  Proposed (20020131)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
3761  CVE-2001-0955  Candidate  Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title.  Proposed (20020131)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
3762  CVE-2001-0956  Candidate  speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell metacharacters.  Proposed (20020131)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
3835  CVE-2001-1031  Candidate  Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command.  Modified (20020228-01)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(2) Foat, Wall    View
5379  CVE-2002-0991  Candidate  Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.  Proposed (20020830)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View

Page 1019 of 20943, showing 5 records out of 104715 total, starting on record 5091, ending on 5095

Actions