CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3788 | CVE-2001-0983 | Candidate | UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges. | Proposed (20020131) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ultraedit-weak-encryption(8696) | View |
3789 | CVE-2001-0984 | Candidate | Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and promp on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords. | Proposed (20020131) | ACCEPT(2) Foat, Frech | MODIFY(1) Green | NOOP(2) Cole, Wall | Green> THE ISSUE OF WHETHER THIS IS PROGRAMMATIC OR OS RELATED SEEMS | UNSETTLED, AS DOES THE LEVEL OF PRIVILEGE THAT CAN BE OBTAINED | View |
3790 | CVE-2001-0985 | Candidate | shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | Green> THIS VULNERABILITY IS SUFFICIENTLY DISTINCT FROM A DIRECTORY | TRANSVERSAL TO WARRANT INCLUSION | View |
3791 | CVE-2001-0986 | Candidate | SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(2) Cole, Foat | REVIEWING(1) Wall | Frech> http://www.kb.cert.org/vuls/id/914859 | View |
3793 | CVE-2001-0988 | Candidate | Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information. | Proposed (20020131) | ACCEPT(2) Cole, Frech | MODIFY(1) Green | NOOP(3) Armstrong, Foat, Wall | Green> SEEMS TO BE CONTRADICTING INFORMATION IN THE MESSAGES AT BUGTRAQ | View |
Page 20763 of 20943, showing 5 records out of 104715 total, starting on record 103811, ending on 103815