CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5800  CVE-2002-1416  Candidate  The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REVIEWING(1) Baker  Baker> See entry for CAN 2002-1415...  View
5799  CVE-2002-1415  Candidate  Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REVIEWING(1) Baker  Baker> There is an updated version available from the vendor"s website, | http://www.51webmail.com/downloadwem.html | however, I am unable to determine whether this bug has been fixed or | not, since the site is in Chinese. There is no english language version | of it, apparently. There is an upgrade notes and patch listing under the | download menu, so if we have someone with chinese language skills, we might | be able to get this one sorted out...  View
5798  CVE-2002-1414  Entry  Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable.        View
5797  CVE-2002-1413  Entry  RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.        View
5796  CVE-2002-1412  Entry  Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script.        View

Page 19784 of 20943, showing 5 records out of 104715 total, starting on record 98916, ending on 98920

Actions