CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4025  CVE-2001-1221  Candidate  D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of "public" which allows remote attackers to gain sensitive information.  Proposed (20020315)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REJECT(1) Ziese  Ziese> candidate? | Frech> XF:nwn-ap-default-snmp-read(6559)  View
3956  CVE-2001-1152  Candidate  Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.  Proposed (20020315)  ACCEPT(2) Baker, Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Green, Wall | REJECT(1) Ziese  Ziese> ACCEPT REASON: Rejection logic makes sense, products have to be used as | intended. Misuse is not a security vulnerability per se. | Frech> XF:content-slash-bypass-filter(6816) | Baker> I would say that this is a vulnerability, since their website | touts URL filtering as a feature of the product. If the product has to | filter URL"s then the product needs to be able to filter URL"s properly, | or the product fails. | Here is the list of features, quoted from their product page for | web sweeper: | | "Key Features | Policy based web security implementation for information posted to and downloaded from the web | Protects against unauthorized users accessing the web utilizing user authentication | Provides URL filtering blocking stopping inappropriate site access | Protects against loss of confidential information, viruses, portable code, and inappropriate content entering and | leaving via web based e-mail accounts such as hotmail and Yahoo | Auditing and reporting on individual and group web traffic | Customizable "Block" and "Progress Message" pages "  View
3301  CVE-2001-0484  Candidate  Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.  Modified (20020223-01)  ACCEPT(1) Renaud | MODIFY(2) Baker, Frech | NOOP(6) Balinsky, Cole, Oliver, Wall, Williams, Ziese | REVIEWING(1) Christey  Williams> there was an issue with admin passwd storage for Tektronix Phaser 360, 740, 780, 840 | Frech> XF:tektronix-phaserlink-webserver-backdoor(6482) | Baker> 750DP and 930 printers should be added | http://www.securityfocus.com/archive/1/181007 | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> CVE-1999-1508 covered the older versions discussed | by Ken Williams. These may be duplicates. | This one is BID:2659 | http://www.securityfocus.com/bid/2659  View
8442  CVE-2004-0014  Candidate  Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall  Williams> need to change desc. i think this was fixed in 0.8.2. | http://www.gohome.org/nd  View
3313  CVE-2001-0496  Candidate  kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.  Modified (20010910-01)  ACCEPT(4) Baker, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Renaud, Wall | REVIEWING(1) Christey  Williams> kdesu is part of kdelibs package. since entire kdelibs package must be upgraded, and since kdelibs (rather than kdesu) is referenced in most advisories related to this issue, we might want to reference kdelibs in this CAN. | Frech> XF:kdelibs-kdesu-insecure-tmpfile(6856) | Christey> Agree with Ken Williams. The CVE descriptions in general | should capture all "reasonable" keywords under which | someone may know the vulnerability. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> It"s possible that this is the same vulnerability as CVE-2001-0178, | but the description is written so differently from the others, that | it"s hard to be sure. In addition, Mandrake released a separate | advisory for CVE-2001-0178. | BID:2669 addresses CVE-2001-0178.  View

Page 2 of 20943, showing 5 records out of 104715 total, starting on record 6, ending on 10

<<first 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 last>>

Actions