CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5059  CVE-2002-0669  Candidate  The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force authentication of incoming calls, which does not notify the user when an authentication failure occurs.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Baker  Baker> I don"t believe that a configuration option by the administrator is a | vulnerability. The fact that the administrator can require authentication | of users attempting to use the service, without notifying users that | are NOT using authentication is not a vulnerability. For example, I | could configure sshd to allow only certain hosts to connect, by means of | a key, and if someone else tried to connect that is not authorized, it | would disallow it. Similarly, the administrator could require authentication | and only notify those users allowed to connect of the necessary authentication | credentials to preclude un-authorized use of the system. The only way I would | see this as a vulnerability was if the change was able to be made without | the proper credentials through some fault in the program, or if there was no way to enable authentication on | any client trying to connect which would render the system unusable to everyone | (but that would still not really be a vulnerability as much as a "stupid | feature") | The ability to make this change afer gaining administrator priveleges by means | of another vulnerability does not make this a vulnerability. I would classify | this as a configuration setting that can severly restrict access, at the discretion | of the administrator.  View
5828  CVE-2002-1444  Candidate  The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5829  CVE-2002-1445  Candidate  Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5833  CVE-2002-1449  Candidate  eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5578  CVE-2002-1194  Candidate  Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View

Page 20916 of 20943, showing 5 records out of 104715 total, starting on record 104576, ending on 104580

Actions