CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8671 | CVE-2004-0243 | Candidate | AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods. | Modified (20050518) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8690 | CVE-2004-0262 | Candidate | Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string. | Modified (20050518) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View | |
8695 | CVE-2004-0267 | Candidate | The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp. | Modified (20050518) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8699 | CVE-2004-0271 | Candidate | Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form. | Modified (20050518) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8470 | CVE-2004-0042 | Candidate | vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames. | Modified (20050526) | ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Wall, Williams | REJECT(1) Cox | Williams> insufficient data. | CHANGE> [Cox changed vote from REVIEWING to REJECT] | Cox> Expected behaviour. By source code analysis the difference in | behaviour mentioned in the report only occurs when an administrator has | configured the server with an explicit userlist - either to allow or deny | all users in the userlist. The vsftpd manual page states that if a | userlist is used then the user will be denied access before they are asked | for a password to help prevent cleartext passwords being transmitted. | Administrators who don"t want this behaviour do not need to configure an | optional userlist. | View |
Page 20420 of 20943, showing 5 records out of 104715 total, starting on record 102096, ending on 102100