CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5065  CVE-2002-0675  Candidate  Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone.  Modified (20050610)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:pingtel-xpressa-firmware-upgrade(9570)  View
5585  CVE-2002-1201  Candidate  IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.  Modified (20050610)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
5587  CVE-2002-1203  Candidate  IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.  Modified (20050610)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
5588  CVE-2002-1204  Candidate  Netscape Communicator 4.x allows attackers to use a link to steal a user"s preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.  Modified (20050610)  NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall    View
5095  CVE-2002-0705  Candidate  The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View

Page 20432 of 20943, showing 5 records out of 104715 total, starting on record 102156, ending on 102160

Actions