CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10822  CVE-2004-2396  Candidate  passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.  Assigned (20050817)  None (candidate not yet proposed)    View
10823  CVE-2004-2397  Candidate  The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.  Assigned (20050817)  None (candidate not yet proposed)    View
10824  CVE-2004-2398  Candidate  Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.  Assigned (20050817)  None (candidate not yet proposed)    View
10825  CVE-2004-2399  Candidate  Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (CPU consumption) via delayed responses to DNS queries.  Assigned (20050817)  None (candidate not yet proposed)    View
10826  CVE-2004-2400  Candidate  WinFTP Server 1.6 stores username and password credentials in plaintext in the datauser.wfd file, which allows local users to gain access to the credentials.  Assigned (20050817)  None (candidate not yet proposed)    View

Page 18983 of 20943, showing 5 records out of 104715 total, starting on record 94911, ending on 94915

Actions