CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7019  CVE-2003-0190  Candidate  OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.  Assigned (20030401)  None (candidate not yet proposed)    View
7020  CVE-2003-0192  Candidate  Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.  Assigned (20030401)  None (candidate not yet proposed)    View
7021  CVE-2003-0193  Candidate  msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").  Assigned (20030401)  None (candidate not yet proposed)    View
7022  CVE-2003-0194  Candidate  tcpdump does not properly drop privileges to the pcap user when starting up.  Assigned (20030401)  None (candidate not yet proposed)    View
7023  CVE-2003-0195  Candidate  CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.  Assigned (20030401)  None (candidate not yet proposed)    View

Page 20293 of 20943, showing 5 records out of 104715 total, starting on record 101461, ending on 101465

Actions