CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4957 | CVE-2002-0566 | Candidate | PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type. | Proposed (20020611) | ACCEPT(5) Alderson, Baker, Cole, Frech, Wall | NOOP(2) Cox, Foat | View | |
4959 | CVE-2002-0568 | Candidate | Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory. | Proposed (20020611) | ACCEPT(4) Alderson, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat | Frech> XF:oracle-appserver-config-file-access(8453) | View |
4961 | CVE-2002-0570 | Candidate | The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key. | Proposed (20020611) | ACCEPT(3) Alderson, Cole, Frech | MODIFY(1) Foat | NOOP(2) Cox, Wall | Foat> A local user can not modify the data. The user needs to root the box | first or at least get UNIX permission to write to the encrypted file system. | This is different than being a local user. | CHANGE> [Cox changed vote from REVIEWING to NOOP] | View |
4969 | CVE-2002-0578 | Candidate | Buffer overflow in 4D WebServer 6.7.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP request with Basic Authentication containing a long (1) user name or (2) password. | Proposed (20020611) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cox, Foat, Wall | Frech> XF:4d-webserver-authentication-bo(8996) | Christey> A very similar issue was reported in the same version: | BUGTRAQ:20020618 4D 6.7 DOS and Buffer Overflow Vulnerability | URL:http://online.securityfocus.com/archive/1/277481 | | That issue is being given a separate CAN, but it may in fact | be a "dupe" of this issue, or at least it may need to be | merged per CD:SF-LOC. | View |
4970 | CVE-2002-0579 | Candidate | WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password. | Proposed (20020611) | ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | View |
Page 104 of 20943, showing 5 records out of 104715 total, starting on record 516, ending on 520