CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6360  CVE-2002-1978  Candidate  IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.  Assigned (20050629)  None (candidate not yet proposed)    View
6359  CVE-2002-1977  Candidate  Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.  Assigned (20050629)  None (candidate not yet proposed)    View
6358  CVE-2002-1976  Candidate  ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.  Assigned (20050629)  None (candidate not yet proposed)    View
6357  CVE-2002-1975  Candidate  Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.  Assigned (20050629)  None (candidate not yet proposed)    View
6356  CVE-2002-1974  Candidate  The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 19672 of 20943, showing 5 records out of 104715 total, starting on record 98356, ending on 98360

Actions