CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5060  CVE-2002-0670  Candidate  The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.  Modified (20050610)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:pingtel-xpressa-plaintext-passwords(9565)  View
1652  CVE-2000-0074  Candidate  PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.  Proposed (20000125)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Christey, Williams  Frech> XF:plusmail-password-permissions | Christey> Re-read the Bugtraq post to make sure the problem is described | properly. The advisory itself is vague as to the nature of | the problem, and the exploit doesn"t help clarify too much. | Christey> Consider adding BID:2653  View
3722  CVE-2001-0916  Candidate  Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition.  Modified (20050703)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:pmake-shell-bo(7603) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement.  View
3721  CVE-2001-0915  Candidate  Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition.  Modified (20050703)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:pmake-shell-format-string(7602) | Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected. | ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z | | This should be sufficient for vendor acknowledgement.  View
2765  CVE-2000-1198  Candidate  qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.  Proposed (20010912)  ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:pop-predictable-lockfile(4335)  View

Page 20840 of 20943, showing 5 records out of 104715 total, starting on record 104196, ending on 104200

Actions