CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1830  CVE-2000-0252  Entry  The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.        View
1829  CVE-2000-0251  Entry  HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.        View
1828  CVE-2000-0250  Candidate  The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.  Proposed (20000426)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:qnx-weak-encryption(4866)  View
1827  CVE-2000-0249  Entry  The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.        View
1826  CVE-2000-0248  Candidate  The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.  Modified (20070924)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | REJECT(1) Cox  Christey> Typo fix: change "passowrd" to "password" | ADDREF BID:1148 | ADDREF URL:http://www.securityfocus.com/bid/1148 | Christey> ADDREF XF:piranha-default-password | Frech> XF:piranha-default-password | In description, passowrd should be password. | Cox> The "execute arbitrary commands" part is a seperate vulnerability, | already assigned CVE-2000-0322. The package was designed to have no | password on installation, so "backdoor" does not apply. When users | install Piranha they are expected to add a password to the web | administration GUI, it"s a documented part of the procedure. "The web | GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux | Piranha package installs with a default password" is accurate if it | qualifies as an exposure. | Christey> BUGTRAQ:20000425 piranha default password/exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95668829621268&w=2 | | Default accounts/passwords need to be accounted for in CVE, | but the question is what level of abstraction to use - a | separate CVE for each password, or one CVE for all passwords, | or somewhere in the middle? That is the crux of CD:CF-PASS.  View

Page 20578 of 20943, showing 5 records out of 104715 total, starting on record 102886, ending on 102890

Actions