CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5059 | CVE-2002-0669 | Candidate | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force authentication of incoming calls, which does not notify the user when an authentication failure occurs. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Baker | Baker> I don"t believe that a configuration option by the administrator is a | vulnerability. The fact that the administrator can require authentication | of users attempting to use the service, without notifying users that | are NOT using authentication is not a vulnerability. For example, I | could configure sshd to allow only certain hosts to connect, by means of | a key, and if someone else tried to connect that is not authorized, it | would disallow it. Similarly, the administrator could require authentication | and only notify those users allowed to connect of the necessary authentication | credentials to preclude un-authorized use of the system. The only way I would | see this as a vulnerability was if the change was able to be made without | the proper credentials through some fault in the program, or if there was no way to enable authentication on | any client trying to connect which would render the system unusable to everyone | (but that would still not really be a vulnerability as much as a "stupid | feature") | The ability to make this change afer gaining administrator priveleges by means | of another vulnerability does not make this a vulnerability. I would classify | this as a configuration setting that can severly restrict access, at the discretion | of the administrator. | View |
5828 | CVE-2002-1444 | Candidate | The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5829 | CVE-2002-1445 | Candidate | Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5833 | CVE-2002-1449 | Candidate | eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5578 | CVE-2002-1194 | Candidate | Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message. | Proposed (20030317) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | View |
Page 20916 of 20943, showing 5 records out of 104715 total, starting on record 104576, ending on 104580