CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3133  CVE-2001-0312  Candidate  IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere"s host aliases list, which will bypass WebSphere processing.  Proposed (20010404)  MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(2) Bishop, Wall  Frech> XF:websphere-plugin-view-source(6435)  View
3200  CVE-2001-0382  Candidate  Computer Associates CCCHarvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(1) Wall  Frech> XF:cccharvest-weak-encryption(6314) | Product name is CCC/Harvest (forward slash); see | http://ca.com/products/descriptions/ccc_harvest.pdf.  View
3145  CVE-2001-0324  Candidate  Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.  Proposed (20010404)  MODIFY(1) Frech | NOOP(2) Cole, Ziese | RECAST(1) LeBlanc | REVIEWING(3) Baker, Bishop, Wall  LeBlanc> Sun"s Java specification does not provide for limits on the | number of sockets that can be opened. We didn"t write the spec, we just | implemented it. Aside from the issue of EX-CLIENT-DOS issues noted in my | comments on CVE-2001-0322, the vuln would need to be recast to show that | the actual problem lies in Java. If the description is recast to show | that the issue is in Sun"s Java specification, then please change my | vote to NOOP, as per the "don"t vote on issues with other vendors" rule. | Frech> XF:win-udp-dos(6070)  View
3288  CVE-2001-0471  Candidate  SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(2) Oliver, Ziese  Frech> XF:ssh-daemon-failed-login(6071) | Oliver> Not clear how much of this is a vulnerability and how much a | problem with site policy.  View
3215  CVE-2001-0397  Candidate  Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese  Frech> XF:silent-runner-helo-bo(6309) | In description, product is called SilentRunner (no space). | See http://www.silentrunner.com/index.html.  View

Page 19841 of 20943, showing 5 records out of 104715 total, starting on record 99201, ending on 99205

Actions