CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3994  CVE-2001-1190  Candidate  The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.  Proposed (20020315)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(1) Foat | REJECT(1) Ziese  Ziese> This candidate should be explicitly defined.  View
3995  CVE-2001-1191  Candidate  WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.  Proposed (20020315)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese  Frech> XF:tivoli-webseal-dos(7716) | http://online.securityfocus.com/archive/1/268124 | Christey> BUGTRAQ:20020417 IBM Security Advisory: IBM Tivoli Policy Director WebSEAL | URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0223.html | | The vendor says that "there is no denial of service | vulnerability" but goes on to describe "a defect related to | the use of SSL junctions between the WebSEAL component and Web | Servers. This defect can cause the WebSEAL component to fail if SSL | junctions are being used, and certain URLs are then passed across | these junctions." This still sounds like a DoS to me, albeit | one that might not appear in all configurations. | | Fix capitalization: "WebSEAL"  View
4507  CVE-2002-0113  Candidate  EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
4508  CVE-2002-0114  Candidate  EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
4510  CVE-2002-0116  Candidate  Palm OS 3.5h and possibly other versions, as used in Handspring Visor and Xircom products, allows remote attackers to cause a denial of service via a TCP connect scan, e.g. from nmap.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall  Green> Caused a full reset on a Visor  View

Page 20782 of 20943, showing 5 records out of 104715 total, starting on record 103906, ending on 103910

Actions