CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4030  CVE-2001-1226  Candidate  AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Foat, Wall, Ziese  Christey> CERT-VN:VU#282403 | URL:http://www.kb.cert.org/vuls/id/282403  View
4143  CVE-2001-1339  Candidate  Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.  Modified (20050323)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> "bas" = "bad"  View
4059  CVE-2001-1255  Candidate  WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> fix typos: "unathorized"; "[TO] the database"  View
4064  CVE-2001-1260  Candidate  Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> Remove extra "the sniffing" phrase.  View
3894  CVE-2001-1090  Candidate  nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese    View

Page 20067 of 20943, showing 5 records out of 104715 total, starting on record 100331, ending on 100335

Actions