CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6040  CVE-2002-1656  Candidate  X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.  Assigned (20050329)  None (candidate not yet proposed)    View
6039  CVE-2002-1655  Candidate  The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request.  Assigned (20050329)  None (candidate not yet proposed)    View
6038  CVE-2002-1654  Candidate  iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.  Assigned (20050329)  None (candidate not yet proposed)    View
6037  CVE-2002-1653  Candidate  Farm9 Cryptcat, when started in server mode with the -e option, does not enable encryption, which allows clients to communicate without encryption despite intended configuration, and may allow remote attackers to sniff sensitive information.  Assigned (20050329)  None (candidate not yet proposed)    View
6036  CVE-2002-1652  Candidate  Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter.  Assigned (20050329)  None (candidate not yet proposed)    View

Page 19736 of 20943, showing 5 records out of 104715 total, starting on record 98676, ending on 98680

Actions