CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3872  CVE-2001-1068  Candidate  qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system.  Proposed (20020131)  ACCEPT(3) Foat, Frech, Green | NOOP(2) Armstrong, Cole | REVIEWING(1) Wall    View
2475  CVE-2000-0906  Candidate  Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.  Proposed (20001129)  ACCEPT(3) Collins, Frech, Mell | NOOP(2) Cole, Wall    View
3173  CVE-2001-0352  Candidate  SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.  Proposed (20010727)  ACCEPT(3) Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall  Frech> XF:3com-ap-wep-key(6232) | Christey> BID:2899 | URL:http://www.securityfocus.com/bid/2899  View
2229  CVE-2000-0653  Candidate  Microsoft Outlook Express allows remote attackers to monitor a user"s email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.  Proposed (20000803)  ACCEPT(3) Cole, Levy, Wall | NOOP(1) LeBlanc | REJECT(1) Frech | REVIEWING(1) Christey  Frech> Is this a duplicate of CVE-2000-0105? I can find no differentiating evidence | to show that this issue is unique. | Christey> I need to look through my email logs to recall whether I | resolved this potential duplicate with Microsoft people. | CHANGE> [Frech changed vote from REVIEWING to REJECT]  View
2322  CVE-2000-0746  Candidate  Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.  Proposed (20000921)  ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Christey> Make sure both BID"s are appropriate | XF:iis-cross-site-scripting | http://xforce.iss.net/static/5156.php | Frech> XF: iis-cross-site-scripting(5156) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> A re-release of MS:MS00-060 indicates that a new variant of | this problem was discovered, but the advisory does not | provide sufficient details to distinguish it from this | candidate. A new candidate is being created, but the | description can"t be written without mentioning this CAN.  View

Page 19959 of 20943, showing 5 records out of 104715 total, starting on record 99791, ending on 99795

Actions