CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3288  CVE-2001-0471  Candidate  SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.  Proposed (20010524)  MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(2) Oliver, Ziese  Frech> XF:ssh-daemon-failed-login(6071) | Oliver> Not clear how much of this is a vulnerability and how much a | problem with site policy.  View
3289  CVE-2001-0472  Candidate  Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.  Proposed (20010524)  ACCEPT(1) Frech | NOOP(4) Cole, Oliver, Wall, Ziese    View
3294  CVE-2001-0477  Candidate  Vulnerability in WebCalendar 0.9.26 allows remote command execution.  Proposed (20010524)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Balinsky, Wall, Ziese | REVIEWING(1) Williams  Frech> XF;webcalendar-execute-commands(6486) | Balinsky> DNS domain of vendor site listed in the advisory no longer exists. | CHANGE> [Balinsky changed vote from NOOP to REVIEWING] | Balinsky> My mistake. It was the ADVISORY site that no longer exists. Not the vendor. | CHANGE> [Balinsky changed vote from REVIEWING to NOOP] | Balinsky> Could not find specific acknowledgement on vendor site. Only | method of validation on the site is slogging through source code.  View
3295  CVE-2001-0478  Candidate  Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.  Proposed (20010524)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:phpmyadmin-sqlphp-include-file(6483) | Christey> Double-check the version number - is it 2.1.0 or 2.2.0? | CONFIRM:http://phpmyadmin.sourceforge.net/ChangeLog.txt | Item 2001-04-28 says "applied security patch from [Secure | Reality] | The patch implies that tbl_replace.php was also affected.  View
3296  CVE-2001-0479  Candidate  Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.  Proposed (20010524)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Balinsky, Cole, Renaud, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:phppgadmin-sqlphp-include-file(6484) | Balinsky> Advisory site no longer exists. There is not enough detail in the advisory, and the vendor does not acknowledge.  View

Page 297 of 20943, showing 5 records out of 104715 total, starting on record 1481, ending on 1485

Actions