CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3133 | CVE-2001-0312 | Candidate | IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere"s host aliases list, which will bypass WebSphere processing. | Proposed (20010404) | MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(2) Bishop, Wall | Frech> XF:websphere-plugin-view-source(6435) | View |
3200 | CVE-2001-0382 | Candidate | Computer Associates CCCHarvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(1) Wall | Frech> XF:cccharvest-weak-encryption(6314) | Product name is CCC/Harvest (forward slash); see | http://ca.com/products/descriptions/ccc_harvest.pdf. | View |
3145 | CVE-2001-0324 | Candidate | Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash. | Proposed (20010404) | MODIFY(1) Frech | NOOP(2) Cole, Ziese | RECAST(1) LeBlanc | REVIEWING(3) Baker, Bishop, Wall | LeBlanc> Sun"s Java specification does not provide for limits on the | number of sockets that can be opened. We didn"t write the spec, we just | implemented it. Aside from the issue of EX-CLIENT-DOS issues noted in my | comments on CVE-2001-0322, the vuln would need to be recast to show that | the actual problem lies in Java. If the description is recast to show | that the issue is in Sun"s Java specification, then please change my | vote to NOOP, as per the "don"t vote on issues with other vendors" rule. | Frech> XF:win-udp-dos(6070) | View |
3288 | CVE-2001-0471 | Candidate | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(2) Oliver, Ziese | Frech> XF:ssh-daemon-failed-login(6071) | Oliver> Not clear how much of this is a vulnerability and how much a | problem with site policy. | View |
3215 | CVE-2001-0397 | Candidate | Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese | Frech> XF:silent-runner-helo-bo(6309) | In description, product is called SilentRunner (no space). | See http://www.silentrunner.com/index.html. | View |
Page 19841 of 20943, showing 5 records out of 104715 total, starting on record 99201, ending on 99205