CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1661  CVE-2000-0083  Entry  HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.        View
1662  CVE-2000-0084  Candidate  CuteFTP uses weak encryption to store password information in its tree.dat file.  Proposed (20000125)  MODIFY(2) Baker, Frech | NOOP(1) Christey  Frech> XF:cuteftp-weak-encrypt(3910) | Christey> BUGTRAQ:20010823 Re: Respondus v1.1.2 stores passwords using weak encryption | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99861651923668&w=2 | This followup to a different thread mentions the sm.dat file | for the site manager. | Baker> The reference from the Bugtraq mentions the sm.dat uses better encryption, but doesn"t really address the tree.dat file.  View
1663  CVE-2000-0085  Candidate  Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.  Proposed (20000125)  ACCEPT(1) Baker | MODIFY(1) Frech  Frech> XF:hotmail-java-execute  View
1664  CVE-2000-0086  Candidate  Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.  Proposed (20000125)  ACCEPT(2) Baker, Williams | MODIFY(1) Frech  Frech> XF:timbuktu-password-cleartext  View
1665  CVE-2000-0087  Entry  Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.        View

Page 333 of 20943, showing 5 records out of 104715 total, starting on record 1661, ending on 1665

Actions