CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1659  CVE-2000-0081  Candidate  Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.  Proposed (20000125)  MODIFY(1) Frech | REJECT(1) Baker  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:hotmail-vascript-java-injection  View
1662  CVE-2000-0084  Candidate  CuteFTP uses weak encryption to store password information in its tree.dat file.  Proposed (20000125)  MODIFY(2) Baker, Frech | NOOP(1) Christey  Frech> XF:cuteftp-weak-encrypt(3910) | Christey> BUGTRAQ:20010823 Re: Respondus v1.1.2 stores passwords using weak encryption | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99861651923668&w=2 | This followup to a different thread mentions the sm.dat file | for the site manager. | Baker> The reference from the Bugtraq mentions the sm.dat uses better encryption, but doesn"t really address the tree.dat file.  View
1663  CVE-2000-0085  Candidate  Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.  Proposed (20000125)  ACCEPT(1) Baker | MODIFY(1) Frech  Frech> XF:hotmail-java-execute  View
1664  CVE-2000-0086  Candidate  Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.  Proposed (20000125)  ACCEPT(2) Baker, Williams | MODIFY(1) Frech  Frech> XF:timbuktu-password-cleartext  View
1671  CVE-2000-0093  Candidate  An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.  Proposed (20000208)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:linux-initial-password-encryption  View

Page 20563 of 20943, showing 5 records out of 104715 total, starting on record 102811, ending on 102815

Actions