CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4695 | CVE-2002-0303 | Candidate | GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password. | Proposed (20020502) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:groupwise-ldap-blank-password(8244) | View |
4694 | CVE-2002-0302 | Entry | The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, which could prevent some alerts from being sent in the event of an attack. | View | |||
4693 | CVE-2002-0301 | Candidate | Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters. | Proposed (20020502) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> XF:nfuse-user-information-disclosure(8257) | URL:http://www.iss.net/security_center/static/8257.php | Frech> XF:nfuse-user-information-disclosure(8257) | View |
4692 | CVE-2002-0300 | Entry | gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file. | View | |||
4691 | CVE-2002-0299 | Entry | CNet CatchUp before 1.3.1 allows attackers to execute arbitrary code via a .RVP file that creates a file with an arbitrary extension (such as .BAT), which is executed during a scan. | View |
Page 20005 of 20943, showing 5 records out of 104715 total, starting on record 100021, ending on 100025