CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4054  CVE-2001-1250  Candidate  vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4057  CVE-2001-1253  Candidate  Alexis 2.0 and 2.1 in COM2001 InternetPBX stores voicemail passwords in plain text in the com2001.ini file, which could allow local users to make long distance calls as other users.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
4058  CVE-2001-1254  Candidate  Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:alexis-http-plaintext-information(7205)  View
4059  CVE-2001-1255  Candidate  WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> fix typos: "unathorized"; "[TO] the database"  View
4061  CVE-2001-1257  Candidate  Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.  Proposed (20020502)  ACCEPT(4) Cole, Cox, Frech, Green | NOOP(2) Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to ACCEPT]  View

Page 146 of 20943, showing 5 records out of 104715 total, starting on record 726, ending on 730

Actions