CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2956  CVE-2001-0135  Candidate  The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.  Proposed (20010214)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:ultraboard-cgi-perm | URL:http://xforce.iss.net/static/5931.php | Frech> XF:ultraboard-cgi-perm(5931) | In description, "writeable": from | http://www.dictionary.com/cgi-bin/dict.pl?term=Writable: Writable | Writ"a*ble, a. Capable of, or suitable for, being written down. | Christey> Yeah yeah yeah, Andre, I knew you"d catch my bad spelling :-)  View
2348  CVE-2000-0772  Candidate  The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password.  Modified (20010116-01)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:tumbleweed-mms-blank-password | http://xforce.iss.net/static/5072.php | Frech> XF:umbleweed-mms-blank-password(5072)  View
2367  CVE-2000-0791  Candidate  Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.  Proposed (20000921)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:trustix-secure-apache-misconfig | http://xforce.iss.net/static/5099.php | Frech> XF:trustix-secure-apache-misconfig(5099)  View
5870  CVE-2002-1486  Candidate  Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Christey, Cox, Wall  Christey> XF:trillian-irc-privmsg-bo(10143) | URL:http://www.iss.net/security_center/static/10143.php | BID:5755 | URL:http://www.securityfocus.com/bid/5755  View
2333  CVE-2000-0757  Candidate  The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.  Proposed (20000921)  ACCEPT(2) Baker, Levy | NOOP(4) Christey, Cole, Wall, Williams  Christey> XF:totalbill-remote-execution | http://xforce.iss.net/static/5068.php  View

Page 268 of 20943, showing 5 records out of 104715 total, starting on record 1336, ending on 1340

Actions