CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3843 | CVE-2001-1039 | Candidate | The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer. | Proposed (20020131) | ACCEPT(2) Foat, Green | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall | Frech> XF:jetdirect-jetadmin-telnet-access(6950) | View |
3844 | CVE-2001-1040 | Candidate | HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password. | Proposed (20020131) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> Not jetdirect-jetadmin-telnet-access(6950). | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:jetdirect-admin-password-reset(8713) | View |
3845 | CVE-2001-1041 | Candidate | oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | REVIEWING(1) Christey | Frech> XF:oracle-binary-symlink(6940) | Possible overlap with CVE-2001-0832 (overlapping | references)? | Christey> Possible dupe with CVE-2001-0832; need to review more closely. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
3846 | CVE-2001-1042 | Candidate | Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file. | Proposed (20020131) | ACCEPT(2) Cole, Frech | NOOP(3) Armstrong, Foat, Wall | REVIEWING(1) Green | View | |
3848 | CVE-2001-1044 | Candidate | Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall | View |
Page 176 of 20943, showing 5 records out of 104715 total, starting on record 876, ending on 880