CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6360 | CVE-2002-1978 | Candidate | IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6359 | CVE-2002-1977 | Candidate | Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6358 | CVE-2002-1976 | Candidate | ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6357 | CVE-2002-1975 | Candidate | Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6356 | CVE-2002-1974 | Candidate | The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root. | Assigned (20050629) | None (candidate not yet proposed) | View |
Page 19672 of 20943, showing 5 records out of 104715 total, starting on record 98356, ending on 98360