CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6976 | CVE-2003-0147 | Candidate | OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server"s private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal). | Modified (20071129) | ACCEPT(4) Baker, Cole, Green, Wall | MODIFY(1) Cox | NOOP(1) Christey | Christey> ENGARDE:ESA-20030320-010 | BUGTRAQ:20030320 [OpenPKG-SA-2003.026] OpenPKG Security Advisory (openssl) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104819602408063&w=2 | Christey> FREEBSD:FreeBSD-SA-03:06.openssl | Cox> Addref:http://www.openssl.org/news/secadv_20030317.txt | Christey> MANDRAKE:MDKSA-2003:035 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:035 | Christey> BUGTRAQ:20030325 GLSA: stunnel (200303-24) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104861762028637&w=2 | | Need to change desc to include stunnel | Cox> REDHAT:RHSA-2003:102 | URL:http://www.redhat.com/support/errata/RHSA-2003-102.html | Cox> REDHAT:RHSA-2003:101 | URL:http://www.redhat.com/support/errata/RHSA-2003-101.html | Christey> CONECTIVA:CLA-2003:625 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000625 | Christey> DEBIAN:DSA-288 | URL:http://www.debian.org/security/2003/dsa-288 | Christey> MANDRAKE:MDKSA-2003:035 | (as suggested by Vincent Danen of Mandrake) | Christey> SGI:20030501-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20030501-01-I | Christey> REDHAT:RHSA-2003:205 | Christey> CERT-VN:VU#997481 | URL:http://www.kb.cert.org/vuls/id/997481 | View |
5488 | CVE-2002-1101 | Candidate | Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | REVIEWING(1) Christey | Christey> Possible dupe of CVE-2002-1100 ?? Need to review the bug log | in the Cisco advisory. | View |
5939 | CVE-2002-1555 | Candidate | Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | View | |
5487 | CVE-2002-1100 | Candidate | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | View | |
5574 | CVE-2002-1190 | Candidate | Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls. | Modified (20080822) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | View |
Page 19919 of 20943, showing 5 records out of 104715 total, starting on record 99591, ending on 99595