CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2956 | CVE-2001-0135 | Candidate | The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs. | Proposed (20010214) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:ultraboard-cgi-perm | URL:http://xforce.iss.net/static/5931.php | Frech> XF:ultraboard-cgi-perm(5931) | In description, "writeable": from | http://www.dictionary.com/cgi-bin/dict.pl?term=Writable: Writable | Writ"a*ble, a. Capable of, or suitable for, being written down. | Christey> Yeah yeah yeah, Andre, I knew you"d catch my bad spelling :-) | View |
2348 | CVE-2000-0772 | Candidate | The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password. | Modified (20010116-01) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:tumbleweed-mms-blank-password | http://xforce.iss.net/static/5072.php | Frech> XF:umbleweed-mms-blank-password(5072) | View |
2367 | CVE-2000-0791 | Candidate | Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse. | Proposed (20000921) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:trustix-secure-apache-misconfig | http://xforce.iss.net/static/5099.php | Frech> XF:trustix-secure-apache-misconfig(5099) | View |
5870 | CVE-2002-1486 | Candidate | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Christey, Cox, Wall | Christey> XF:trillian-irc-privmsg-bo(10143) | URL:http://www.iss.net/security_center/static/10143.php | BID:5755 | URL:http://www.securityfocus.com/bid/5755 | View |
2333 | CVE-2000-0757 | Candidate | The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed. | Proposed (20000921) | ACCEPT(2) Baker, Levy | NOOP(4) Christey, Cole, Wall, Williams | Christey> XF:totalbill-remote-execution | http://xforce.iss.net/static/5068.php | View |
Page 268 of 20943, showing 5 records out of 104715 total, starting on record 1336, ending on 1340