CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6976  CVE-2003-0147  Candidate  OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server"s private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).  Modified (20071129)  ACCEPT(4) Baker, Cole, Green, Wall | MODIFY(1) Cox | NOOP(1) Christey  Christey> ENGARDE:ESA-20030320-010 | BUGTRAQ:20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104819602408063&w=2 | Christey> FREEBSD:FreeBSD-SA-03:06.openssl | Cox> Addref:http://www.openssl.org/news/secadv_20030317.txt | Christey> MANDRAKE:MDKSA-2003:035 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035 | Christey> BUGTRAQ:20030325 GLSA: stunnel (200303-24) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104861762028637&w=2 | | Need to change desc to include stunnel | Cox> REDHAT:RHSA-2003:102 | URL:http://www.redhat.com/support/errata/RHSA-2003-102.html | Cox> REDHAT:RHSA-2003:101 | URL:http://www.redhat.com/support/errata/RHSA-2003-101.html | Christey> CONECTIVA:CLA-2003:625 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000625 | Christey> DEBIAN:DSA-288 | URL:http://www.debian.org/security/2003/dsa-288 | Christey> MANDRAKE:MDKSA-2003:035 | (as suggested by Vincent Danen of Mandrake) | Christey> SGI:20030501-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I | Christey> REDHAT:RHSA-2003:205 | Christey> CERT-VN:VU#997481 | URL:http://www.kb.cert.org/vuls/id/997481  View
5488  CVE-2002-1101  Candidate  Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | REVIEWING(1) Christey  Christey> Possible dupe of CVE-2002-1100 ?? Need to review the bug log | in the Cisco advisory.  View
5939  CVE-2002-1555  Candidate  Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox    View
5487  CVE-2002-1100  Candidate  Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox    View
5574  CVE-2002-1190  Candidate  Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.  Modified (20080822)  ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox    View

Page 19919 of 20943, showing 5 records out of 104715 total, starting on record 99591, ending on 99595

Actions