CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2509  CVE-2000-0940  Candidate  Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.  Proposed (20001129)  ACCEPT(2) Frech, Mell | NOOP(1) Cole    View
2519  CVE-2000-0950  Candidate  Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.  Proposed (20001129)  ACCEPT(4) Baker, Cole, Frech, Mell | NOOP(1) Renaud | REVIEWING(1) Christey  Christey> I thought I saw some mailing list that questioned whether this | problem was only a DoS...  View
2523  CVE-2000-0954  Candidate  Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.  Proposed (20001129)  ACCEPT(3) Baker, Frech, Mell | NOOP(1) Cole    View
2524  CVE-2000-0955  Candidate  Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.  Proposed (20001129)  ACCEPT(4) Cole, Frech, Mell, Ziese | NOOP(2) Balinsky, Christey  Christey> CISCO:20001026 VCO/4K Remote Password Disclosure | http://www.cisco.com/warp/public/707/vco4kpasswdexposure-pub.shtml | CHANGE> [Balinsky changed vote from REVIEWING to NOOP]  View
2540  CVE-2000-0971  Candidate  Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.  Proposed (20001129)  ACCEPT(3) Cole, Frech, Mell | NOOP(2) Armstrong, Christey  Christey> Fix typo: "possible" should be "possibly" | Christey> fix typo: "and possible"  View

Page 339 of 20943, showing 5 records out of 104715 total, starting on record 1691, ending on 1695

Actions