CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3288 | CVE-2001-0471 | Candidate | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack. | Proposed (20010524) | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(2) Oliver, Ziese | Frech> XF:ssh-daemon-failed-login(6071) | Oliver> Not clear how much of this is a vulnerability and how much a | problem with site policy. | View |
3289 | CVE-2001-0472 | Candidate | Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request. | Proposed (20010524) | ACCEPT(1) Frech | NOOP(4) Cole, Oliver, Wall, Ziese | View | |
3294 | CVE-2001-0477 | Candidate | Vulnerability in WebCalendar 0.9.26 allows remote command execution. | Proposed (20010524) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Balinsky, Wall, Ziese | REVIEWING(1) Williams | Frech> XF;webcalendar-execute-commands(6486) | Balinsky> DNS domain of vendor site listed in the advisory no longer exists. | CHANGE> [Balinsky changed vote from NOOP to REVIEWING] | Balinsky> My mistake. It was the ADVISORY site that no longer exists. Not the vendor. | CHANGE> [Balinsky changed vote from REVIEWING to NOOP] | Balinsky> Could not find specific acknowledgement on vendor site. Only | method of validation on the site is slogging through source code. | View |
3295 | CVE-2001-0478 | Candidate | Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. | Proposed (20010524) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:phpmyadmin-sqlphp-include-file(6483) | Christey> Double-check the version number - is it 2.1.0 or 2.2.0? | CONFIRM:http://phpmyadmin.sourceforge.net/ChangeLog.txt | Item 2001-04-28 says "applied security patch from [Secure | Reality] | The patch implies that tbl_replace.php was also affected. | View |
3296 | CVE-2001-0479 | Candidate | Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script. | Proposed (20010524) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Balinsky, Cole, Renaud, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:phppgadmin-sqlphp-include-file(6484) | Balinsky> Advisory site no longer exists. There is not enough detail in the advisory, and the vendor does not acknowledge. | View |
Page 297 of 20943, showing 5 records out of 104715 total, starting on record 1481, ending on 1485