CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3575  CVE-2001-0768  Candidate  GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.  Proposed (20011012)  ACCEPT(2) Baker, Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Baker> Vendor added password encryption in latest version, 0.996, and you can see the comments in the changes log, at the following URL: | | www.nitrolic.com/main.htm | Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002  View
2350  CVE-2000-0774  Candidate  The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.  Proposed (20000921)  ACCEPT(3) Baker, Levy, Williams | NOOP(2) Cole, Wall  Baker> Vendor fixed this issue in later version of the software  View
76  CVE-1999-0076  Candidate  Buffer overflow in wu-ftp from PASV command causes a core dump.  Modified (19990925-01)  ACCEPT(3) Baker, Frech, Ozancin | NOOP(1) Balinsky | REVIEWING(1) Christey  Balinsky> Don"t know what this is. Is this the LIST Core dump vulnerability? | Christey> Need to add more references and details.  View
1106  CVE-1999-1126  Candidate  Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".  Proposed (20010912)  ACCEPT(5) Armstrong, Cole, Foat, Frech, Stracener | NOOP(1) Wall | REJECT(1) Balinsky  Balinsky> Duplicate of CVE-1999-1042  View
5596  CVE-2002-1212  Candidate  Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.  Modified (20071101)  ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall  Balinsky> Links to software are dead. Cannot verify.  View

Page 20580 of 20943, showing 5 records out of 104715 total, starting on record 102896, ending on 102900

Actions