CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4800  CVE-2002-0408  Candidate  htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.  Proposed (20020611)  ACCEPT(1) Alderson | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:lotus-domino-reveal-information(8160)  View
4814  CVE-2002-0422  Candidate  IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.  Modified (20070919)  ACCEPT(1) Alderson | MODIFY(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:iis-request-ip-disclosure(8385)  View
768  CVE-1999-0788  Entry  Arkiea nlservd allows remote attackers to conduct a denial of service.        View
1024  CVE-1999-1044  Entry  Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.        View
1536  CVE-1999-1556  Entry  Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.        View

Page 20333 of 20943, showing 5 records out of 104715 total, starting on record 101661, ending on 101665

Actions