CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3575 | CVE-2001-0768 | Candidate | GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file. | Proposed (20011012) | ACCEPT(2) Baker, Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Baker> Vendor added password encryption in latest version, 0.996, and you can see the comments in the changes log, at the following URL: | | www.nitrolic.com/main.htm | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002 | View |
69111 | CVE-2014-1816 | Candidate | Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability." | Assigned (20140129) | None (candidate not yet proposed) | View | |
69367 | CVE-2014-2072 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20140219) | None (candidate not yet proposed) | View | |
4087 | CVE-2001-1283 | Candidate | The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:imail-dot-mailbox-dos(7277) | View |
69623 | CVE-2014-2328 | Candidate | lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors. | Assigned (20140312) | None (candidate not yet proposed) | View |
Page 20232 of 20943, showing 5 records out of 104715 total, starting on record 101156, ending on 101160