CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1636 | CVE-2000-0058 | Candidate | Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files. | Proposed (20000125) | MODIFY(2) Baker, Frech | NOOP(1) Christey | Frech> XF:handspring-visor-auth(3873) | Consider removing the security-express.com reference, since it is identical | to the BugTraq reference. The BugTraq reference is (hopefully) not going to | disappear soon, and the security-express.com reference provides no new or | additional information. | Christey> URLs will begin to be included with candidates to support | Board members" voting activities. They will be converted to | the generalized reference format when if candidate is | ACCEPTed and becomes an official entry. | Christey> The problem may not be a lack of authentication (as mentioned | by the poster), but rather weak authentication (the apparent | need to provide the same username). | Baker> MOdify description to indicate the weak authentication | View |
3709 | CVE-2001-0903 | Candidate | Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication. | Modified (20050703) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:hdcp-authentication-keys(7612) | View |
3033 | CVE-2001-0212 | Candidate | Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters. | Proposed (20010309) | MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese | Frech> XF:his-auktion-cgi-url(6090) | View |
3551 | CVE-2001-0744 | Candidate | Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file. | Proposed (20011012) | ACCEPT(4) Armstrong, Baker, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:horde-popen-remote-access(5244) | Christey> Need to examine the codebase relationship between Horde and | IMP. | Christey> BID:3066 | URL:http://online.securityfocus.com/bid/3066 | View |
1663 | CVE-2000-0085 | Candidate | Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag. | Proposed (20000125) | ACCEPT(1) Baker | MODIFY(1) Frech | Frech> XF:hotmail-java-execute | View |
Page 20775 of 20943, showing 5 records out of 104715 total, starting on record 103871, ending on 103875