CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7020  CVE-2003-0192  Candidate  Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.  Assigned (20030401)  None (candidate not yet proposed)    View
7019  CVE-2003-0190  Candidate  OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.  Assigned (20030401)  None (candidate not yet proposed)    View
7018  CVE-2003-0189  Candidate  The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.  Assigned (20030401)  None (candidate not yet proposed)    View
7017  CVE-2003-0188  Candidate  lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.  Assigned (20030401)  None (candidate not yet proposed)    View
7016  CVE-2003-0187  Candidate  The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20"s support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.  Assigned (20030401)  None (candidate not yet proposed)    View

Page 19540 of 20943, showing 5 records out of 104715 total, starting on record 97696, ending on 97700

Actions