CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5248 | CVE-2002-0858 | Candidate | catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges. | Modified (20071101) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:oracle-catsnmp-default-account(9932) | View |
5065 | CVE-2002-0675 | Candidate | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone. | Modified (20050610) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:pingtel-xpressa-firmware-upgrade(9570) | View |
3587 | CVE-2001-0780 | Candidate | Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter. | Proposed (20011012) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:directory-pro-directory-traversal(6632) | All references point to CGI with the name of | directorypro.cgi, not cosmicpro.cgi as listed in description. | Christey> Not sure how cosmicpro.cgi got in there. It should be | directorypro.cgi as indicated by Andre. | View |
3704 | CVE-2001-0898 | Candidate | Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript that uses setTimeout to (1) access data after a new window to the domain has been opened or (2) access data via about:cache. | Modified (20050703) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:opera-java-cross-site(7567) | Christey> XF:opera-java-cross-site(7567) | URL:http://www.iss.net/security_center/static/7567.php | BID:3553 | URL:http://www.securityfocus.com/bid/3553 | | Some people are calling this XSS, but is it? | View |
3565 | CVE-2001-0758 | Candidate | Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command. | Proposed (20011012) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:shambala-ftp-cwd-directory-traversal(7418) | Christey> Other .. problems were found in 4.5 as described in: | BUGTRAQ:20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0282.html | CD:SF-LOC might suggest merging these two. (I"m working | on creating a CAN for the newer discovery). | View |
Page 19796 of 20943, showing 5 records out of 104715 total, starting on record 98976, ending on 98980