CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3843  CVE-2001-1039  Candidate  The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.  Proposed (20020131)  ACCEPT(2) Foat, Green | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:jetdirect-jetadmin-telnet-access(6950)  View
3844  CVE-2001-1040  Candidate  HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> Not jetdirect-jetadmin-telnet-access(6950). | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:jetdirect-admin-password-reset(8713)  View
3845  CVE-2001-1041  Candidate  oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | REVIEWING(1) Christey  Frech> XF:oracle-binary-symlink(6940) | Possible overlap with CVE-2001-0832 (overlapping | references)? | Christey> Possible dupe with CVE-2001-0832; need to review more closely. | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3846  CVE-2001-1042  Candidate  Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.  Proposed (20020131)  ACCEPT(2) Cole, Frech | NOOP(3) Armstrong, Foat, Wall | REVIEWING(1) Green    View
3848  CVE-2001-1044  Candidate  Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall    View

Page 176 of 20943, showing 5 records out of 104715 total, starting on record 876, ending on 880

Actions