CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6410 | CVE-2002-2028 | Candidate | The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6409 | CVE-2002-2027 | Candidate | Database of Our Owlish Wisdom (DOOW) 0.1 through 0.2.1 does not properly verify user permissions, which allows remote attackers to perform unauthorized activities. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6408 | CVE-2002-2026 | Candidate | Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6407 | CVE-2002-2025 | Candidate | Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6406 | CVE-2002-2024 | Candidate | Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 19662 of 20943, showing 5 records out of 104715 total, starting on record 98306, ending on 98310