CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1853  CVE-2000-0275  Candidate  CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user"s PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.  Proposed (20000426)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:cryptoadmin-weak-encryption  View
2277  CVE-2000-0701  Candidate  The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.  Modified (20040818)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:gnu-mailman-format-string | You can perhaps normalize Bugtraq URL to CONFIRM:http://www.securityfocus.com/archive/1/73355.  View
3971  CVE-2001-1167  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2001-0976. Reason: This candidate is a duplicate of CVE-2001-0976. Notes: CVE-2001-0976 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Proposed (20020315)  ACCEPT(3) Baker, Cole, Green | NOOP(4) Armstrong, Foat, Wall, Ziese | REJECT(2) Christey, Frech  Frech> DUPE:CVE-2001-0976 | References and descriptions overlap. Currently assigned to | XF:hp-prm-privilege-elevation(7050). | Christey> Agreed, it"s a dupe. CVE-2001-0976 will be preferred, since | it"s been public longer.  View
4872  CVE-2002-0480  Candidate  ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow remote attackers to gain access to the device during installation.  Proposed (20020611)  ACCEPT(3) Baker, Cole, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Frech    View
5705  CVE-2002-1321  Candidate  Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain "Now Playing" options on a downloaded file with a long filename.  Modified (20050708)  ACCEPT(3) Baker, Cole, Green | NOOP(3) Christey, Cox, Wall  Christey> fix typo: "long long"  View

Page 20008 of 20943, showing 5 records out of 104715 total, starting on record 100036, ending on 100040

Actions