CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5271  CVE-2002-0881  Candidate  Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.  Proposed (20020830)  ACCEPT(6) Alderson, Armstrong, Baker, Cole, Foat, Frech | MODIFY(1) Jones | NOOP(1) Cox  Jones> Description: "...use a default, publicly-known, and unchangeable | trusted path key combination to access configuration information, which | allows attackers..."  View
5272  CVE-2002-0882  Candidate  The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.  Proposed (20020830)  ACCEPT(5) Alderson, Cole, Foat, Frech, Jones | NOOP(2) Armstrong, Cox | RECAST(1) Baker    View
5273  CVE-2002-0883  Candidate  Vulnerability in Compaq ProLiant BL e-Class Integrated Administrator 1.0 and 1.10, allows authenticated users with Telnet, SSH, or console access to conduct unauthorized activities.  Proposed (20020830)  ACCEPT(6) Alderson, Armstrong, Baker, Cole, Frech, Jones | NOOP(2) Cox, Foat    View
5274  CVE-2002-0884  Candidate  Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error.  Proposed (20020830)  ACCEPT(5) Alderson, Armstrong, Baker, Cole, Frech | MODIFY(1) Jones | NOOP(3) Christey, Cox, Foat  Jones> Suggest description: "...allows remote attackers to execute | arbitrary code via the functions (1) syserr and | (2) error." | Christey> Correction: this is a RARP (Reverse Address Resolution | Protocol) server. | | A colleague of mine with access to Solaris source has noted | that the affected syslog calls can not be fed user-supplied | data, at least for Solaris; if so, then this is not a vulnerability. | Baker> I think you leave the description as it specifies how the attacker is able to execute arbitrary commands.  View
5275  CVE-2002-0885  Candidate  Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Frech | MODIFY(1) Alderson | NOOP(5) Armstrong, Christey, Cox, Foat, Jones  Jones> Need clarification/verification. | Alderson> Personally, since this one is not only vague, but extremely vague | and not even confirmed, I believe it should be lumped with the previous one | that has been confirmed and is much less vague. | Christey> Correction: this is a RARP (Reverse Address Resolution | Protocol) server. | A colleague of mine with access to Solaris source has noted | that the affected syslog calls can not be fed user-supplied | data, at least for Solaris; if so, then this is not a vulnerability.  View

Page 1055 of 20943, showing 5 records out of 104715 total, starting on record 5271, ending on 5275

Actions