CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4957  CVE-2002-0566  Candidate  PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.  Proposed (20020611)  ACCEPT(5) Alderson, Baker, Cole, Frech, Wall | NOOP(2) Cox, Foat    View
4959  CVE-2002-0568  Candidate  Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  Frech> XF:oracle-appserver-config-file-access(8453)  View
4961  CVE-2002-0570  Candidate  The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | MODIFY(1) Foat | NOOP(2) Cox, Wall  Foat> A local user can not modify the data. The user needs to root the box | first or at least get UNIX permission to write to the encrypted file system. | This is different than being a local user. | CHANGE> [Cox changed vote from REVIEWING to NOOP]  View
4969  CVE-2002-0578  Candidate  Buffer overflow in 4D WebServer 6.7.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP request with Basic Authentication containing a long (1) user name or (2) password.  Proposed (20020611)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cox, Foat, Wall  Frech> XF:4d-webserver-authentication-bo(8996) | Christey> A very similar issue was reported in the same version: | BUGTRAQ:20020618 4D 6.7 DOS and Buffer Overflow Vulnerability | URL:http://online.securityfocus.com/archive/1/277481 | | That issue is being given a separate CAN, but it may in fact | be a "dupe" of this issue, or at least it may need to be | merged per CD:SF-LOC.  View
4970  CVE-2002-0579  Candidate  WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 104 of 20943, showing 5 records out of 104715 total, starting on record 516, ending on 520

Actions