CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3253 | CVE-2001-0435 | Candidate | The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese | Frech> XF:nai-pgp-split-keys(6341) | View |
3288 | CVE-2001-0471 | Candidate | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(2) Oliver, Ziese | Frech> XF:ssh-daemon-failed-login(6071) | Oliver> Not clear how much of this is a vulnerability and how much a | problem with site policy. | View |
3145 | CVE-2001-0324 | Candidate | Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash. | Proposed (20010404) | MODIFY(1) Frech | NOOP(2) Cole, Ziese | RECAST(1) LeBlanc | REVIEWING(3) Baker, Bishop, Wall | LeBlanc> Sun"s Java specification does not provide for limits on the | number of sockets that can be opened. We didn"t write the spec, we just | implemented it. Aside from the issue of EX-CLIENT-DOS issues noted in my | comments on CVE-2001-0322, the vuln would need to be recast to show that | the actual problem lies in Java. If the description is recast to show | that the issue is in Sun"s Java specification, then please change my | vote to NOOP, as per the "don"t vote on issues with other vendors" rule. | Frech> XF:win-udp-dos(6070) | View |
3200 | CVE-2001-0382 | Candidate | Computer Associates CCCHarvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(1) Wall | Frech> XF:cccharvest-weak-encryption(6314) | Product name is CCC/Harvest (forward slash); see | http://ca.com/products/descriptions/ccc_harvest.pdf. | View |
3102 | CVE-2001-0281 | Candidate | Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges. | Proposed (20010404) | MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(2) Bishop, Wall | Frech> XF:dbgprint-format-string(6441) | View |
Page 1103 of 20943, showing 5 records out of 104715 total, starting on record 5511, ending on 5515