CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6878  CVE-2003-0049  Candidate  Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.  Modified (20071022)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  Baker> Realizing they have acknowledged the problem, and provided a fix by allowing the administrator to select whether or not this is allowed, | I am not sure this should really be a vulnerability. If you are the administrator on a system, there are other ways I can become a user | on a system. The fact that you are the administrator (root) you can do almost anything to the system you want, including accessing files | and programs that belong to other users. From a security standpoint, if the system gets "hacked" and the administrator account is compromised, | how big of an issue is it really that the administrator can now access regular user accounts with the administrator password? I am not sure this | should really be a vulnerability. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]  View
5613  CVE-2002-1229  Candidate  Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.  Modified (20050313)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall    View
6903  CVE-2003-0074  Candidate  Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.  Modified (20080326)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall    View
6905  CVE-2003-0076  Candidate  Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall    View
5937  CVE-2002-1553  Candidate  Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Jones    View

Page 20010 of 20943, showing 5 records out of 104715 total, starting on record 100046, ending on 100050

Actions