CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3575 | CVE-2001-0768 | Candidate | GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file. | Proposed (20011012) | ACCEPT(2) Baker, Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Baker> Vendor added password encryption in latest version, 0.996, and you can see the comments in the changes log, at the following URL: | | www.nitrolic.com/main.htm | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002 | View |
2350 | CVE-2000-0774 | Candidate | The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root. | Proposed (20000921) | ACCEPT(3) Baker, Levy, Williams | NOOP(2) Cole, Wall | Baker> Vendor fixed this issue in later version of the software | View |
76 | CVE-1999-0076 | Candidate | Buffer overflow in wu-ftp from PASV command causes a core dump. | Modified (19990925-01) | ACCEPT(3) Baker, Frech, Ozancin | NOOP(1) Balinsky | REVIEWING(1) Christey | Balinsky> Don"t know what this is. Is this the LIST Core dump vulnerability? | Christey> Need to add more references and details. | View |
1106 | CVE-1999-1126 | Candidate | Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_". | Proposed (20010912) | ACCEPT(5) Armstrong, Cole, Foat, Frech, Stracener | NOOP(1) Wall | REJECT(1) Balinsky | Balinsky> Duplicate of CVE-1999-1042 | View |
5596 | CVE-2002-1212 | Candidate | Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. | Modified (20071101) | ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall | Balinsky> Links to software are dead. Cannot verify. | View |
Page 20580 of 20943, showing 5 records out of 104715 total, starting on record 102896, ending on 102900