CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3795  CVE-2001-0990  Candidate  Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3796  CVE-2001-0991  Candidate  Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(4) Armstrong, Cole, Foat, Wall  CHANGE> [Green changed vote from REVIEWING to ACCEPT]  View
3797  CVE-2001-0992  Candidate  shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3799  CVE-2001-0994  Candidate  Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green    View
3801  CVE-2001-0996  Candidate  POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that could cause clients to crash or otherwise behave unexpectedly.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View

Page 188 of 20943, showing 5 records out of 104715 total, starting on record 936, ending on 940

Actions