CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5060 | CVE-2002-0670 | Candidate | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing. | Modified (20050610) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:pingtel-xpressa-plaintext-passwords(9565) | View |
1652 | CVE-2000-0074 | Candidate | PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. | Proposed (20000125) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Christey, Williams | Frech> XF:plusmail-password-permissions | Christey> Re-read the Bugtraq post to make sure the problem is described | properly. The advisory itself is vague as to the nature of | the problem, and the exploit doesn"t help clarify too much. | Christey> Consider adding BID:2653 | View |
3722 | CVE-2001-0916 | Candidate | Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition. | Modified (20050703) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:pmake-shell-bo(7603) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement. | View |
3721 | CVE-2001-0915 | Candidate | Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition. | Modified (20050703) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:pmake-shell-format-string(7602) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement. | View |
2765 | CVE-2000-1198 | Candidate | qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes. | Proposed (20010912) | ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:pop-predictable-lockfile(4335) | View |
Page 20840 of 20943, showing 5 records out of 104715 total, starting on record 104196, ending on 104200