CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3890  CVE-2001-1086  Candidate  XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.  Proposed (20020315)  ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall    View
3891  CVE-2001-1087  Candidate  The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.  Proposed (20020315)  ACCEPT(1) Frech | NOOP(6) Armstrong, Cole, Foat, Green, Wall, Ziese    View
3894  CVE-2001-1090  Candidate  nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese    View
3895  CVE-2001-1091  Candidate  The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.  Proposed (20020315)  ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall    View
3896  CVE-2001-1092  Candidate  msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.  Proposed (20020315)  ACCEPT(1) Frech | NOOP(6) Armstrong, Cole, Foat, Green, Wall, Ziese  CHANGE> [Green changed vote from REVIEWING to NOOP]  View

Page 20769 of 20943, showing 5 records out of 104715 total, starting on record 103841, ending on 103845

Actions