CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3529  CVE-2001-0721  Candidate  Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.  Proposed (20011122)  ACCEPT(3) Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | RECAST(3) Armstrong, Baker, Bishop  Bishop> I agree that these should be split, as the abstraction says. | Frech> XF:win-upnp-dos(7428) | Baker> SPLIT | Armstrong> SPLIT | Christey> Consider adding BID:3499 | Christey> CIAC:M-015 | URL:http://www.ciac.org/ciac/bulletins/m-015.shtml | XF:win-upnp-dos(7428) | URL:http://www.iss.net/security_center/static/7428.php | BID:3499 | URL:http://www.securityfocus.com/bid/3499  View
3843  CVE-2001-1039  Candidate  The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.  Proposed (20020131)  ACCEPT(2) Foat, Green | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:jetdirect-jetadmin-telnet-access(6950)  View
3844  CVE-2001-1040  Candidate  HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> Not jetdirect-jetadmin-telnet-access(6950). | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:jetdirect-admin-password-reset(8713)  View
3845  CVE-2001-1041  Candidate  oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | REVIEWING(1) Christey  Frech> XF:oracle-binary-symlink(6940) | Possible overlap with CVE-2001-0832 (overlapping | references)? | Christey> Possible dupe with CVE-2001-0832; need to review more closely. | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3846  CVE-2001-1042  Candidate  Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.  Proposed (20020131)  ACCEPT(2) Cole, Frech | NOOP(3) Armstrong, Foat, Wall | REVIEWING(1) Green    View

Page 20752 of 20943, showing 5 records out of 104715 total, starting on record 103756, ending on 103760

Actions