CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1636  CVE-2000-0058  Candidate  Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.  Proposed (20000125)  MODIFY(2) Baker, Frech | NOOP(1) Christey  Frech> XF:handspring-visor-auth(3873) | Consider removing the security-express.com reference, since it is identical | to the BugTraq reference. The BugTraq reference is (hopefully) not going to | disappear soon, and the security-express.com reference provides no new or | additional information. | Christey> URLs will begin to be included with candidates to support | Board members" voting activities. They will be converted to | the generalized reference format when if candidate is | ACCEPTed and becomes an official entry. | Christey> The problem may not be a lack of authentication (as mentioned | by the poster), but rather weak authentication (the apparent | need to provide the same username). | Baker> MOdify description to indicate the weak authentication  View
3709  CVE-2001-0903  Candidate  Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.  Modified (20050703)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:hdcp-authentication-keys(7612)  View
3033  CVE-2001-0212  Candidate  Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.  Proposed (20010309)  MODIFY(1) Frech | NOOP(3) Cole, Lawler, Ziese  Frech> XF:his-auktion-cgi-url(6090)  View
3551  CVE-2001-0744  Candidate  Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.  Proposed (20011012)  ACCEPT(4) Armstrong, Baker, Cole, Foat | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:horde-popen-remote-access(5244) | Christey> Need to examine the codebase relationship between Horde and | IMP. | Christey> BID:3066 | URL:http://online.securityfocus.com/bid/3066  View
1663  CVE-2000-0085  Candidate  Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.  Proposed (20000125)  ACCEPT(1) Baker | MODIFY(1) Frech  Frech> XF:hotmail-java-execute  View

Page 20775 of 20943, showing 5 records out of 104715 total, starting on record 103871, ending on 103875

Actions