CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4079 | CVE-2001-1275 | Candidate | MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking. | Proposed (20020502) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Christey | Christey> CALDERA:CSSA-2001-006.0 specifically says they"re not | vulnerable to this issue. So, do we remove the reference | (because they aren"t affected by this problem), or do we | keep the reference because it specifically mentions this | issue? | | Need to review the other advisories; they don"t necessarily | have the details to know whether they"re addressing this | problem or not (the overflow mentioned in these refs is | covered by CVE-2001-1274). MANDRAKE:MDKSA-2001:014 | clearly identifies this issue. | | FREEBSD:FreeBSD-SA-01:16 discussed "remote vulerabilities" | (plural), which *could* include this issue, but it is not | absolutely certain. REDHAT:RHSA-2001:003 refers to | "information protection issues," but that"s not clear enough | either. | | Thanks to John Segura of secureinfo.com for noticing this | issue. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mysql-show-grants-password(9996) | View |
4591 | CVE-2002-0199 | Candidate | Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes. | Proposed (20020502) | ACCEPT(1) Green | NOOP(4) Christey, Cole, Foat, Wall | Christey> XF:shoutcast-admin-cgi-dos(7958) | URL:http://xforce.iss.net/static/7958.php | View |
4593 | CVE-2002-0201 | Candidate | Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View | |
4082 | CVE-2001-1278 | Candidate | Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags. | Proposed (20020502) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Foat | REJECT(3) Christey, Cox, Frech | Christey> Agreed; dupe of CVE-2001-1227 | View |
4594 | CVE-2002-0202 | Candidate | PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) modify the server configuration via the world-writeable /oekaki/ folder. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View |
Page 20823 of 20943, showing 5 records out of 104715 total, starting on record 104111, ending on 104115