CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8671  CVE-2004-0243  Candidate  AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8690  CVE-2004-0262  Candidate  Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.  Modified (20050518)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
8695  CVE-2004-0267  Candidate  The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8699  CVE-2004-0271  Candidate  Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8470  CVE-2004-0042  Candidate  vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.  Modified (20050526)  ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Wall, Williams | REJECT(1) Cox  Williams> insufficient data. | CHANGE> [Cox changed vote from REVIEWING to REJECT] | Cox> Expected behaviour. By source code analysis the difference in | behaviour mentioned in the report only occurs when an administrator has | configured the server with an explicit userlist - either to allow or deny | all users in the userlist. The vsftpd manual page states that if a | userlist is used then the user will be denied access before they are asked | for a password to help prevent cleartext passwords being transmitted. | Administrators who don"t want this behaviour do not need to configure an | optional userlist.  View

Page 20420 of 20943, showing 5 records out of 104715 total, starting on record 102096, ending on 102100

Actions