CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4128  CVE-2001-1324  Candidate  cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.  Modified (20050526)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:idtools-cmvlogin-root-privileges(9987)  View
4650  CVE-2002-0258  Candidate  Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user"s answer or forward URLs.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:icewarp-static-sessionid(9807)  View
1659  CVE-2000-0081  Candidate  Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.  Proposed (20000125)  MODIFY(1) Frech | REJECT(1) Baker  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:hotmail-vascript-java-injection  View
4884  CVE-2002-0492  Candidate  dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.  Proposed (20020611)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:dscshop-cgi-delete-setup(9854)  View
555  CVE-1999-0571  Candidate  A router"s configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.  Modified (20020312-01)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Christey, Northcutt  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ascend-config-kill(889) | XF:cisco-ios-crash(1238) | XF:webramp-remote-access(1670) | XF:ascom-timeplex-debug(1824) | XF:netopia-unpassworded(1850) | XF:cisco-web-crash(1886) | XF:cisco-router-commands(1951) | XF:motorola-cable-default-pass(2002) | XF:default-flowpoint(2091) | XF:netgear-router-idle-dos(4003) | XF:cisco-cbos-telnet(4251) | XF:routermate-snmp-community(4290) | XF:cayman-router-dos(4479) | XF:wavelink-authentication(5185) | XF:ciscosecure-ldap-bypass-authentication(5274) | XF:foundry-firmware-telnet-dos(5514) | XF:netopia-view-system-log(5536) | XF:cisco-webadmin-remote-dos(5595) | XF:cisco-cbos-web-access(5626) | XF:netopia-telnet-dos(6001) | XF:cisco-sn-gain-access(6827) | XF:cayman-dsl-insecure-permissions(6841) | XF:linksys-etherfast-reveal-passwords(6949) | XF:zyxel-router-default-password(6968) | XF:cisco-cbos-web-config(7027) | XF:prestige-wan-bypass-filter(7146) | Christey> I changed the description to make it more explicit that this | candidate is about router configuration, as opposed to | vulnerabilities that accidentally make a configuration | service accessible to anyone.  View

Page 348 of 20943, showing 5 records out of 104715 total, starting on record 1736, ending on 1740

Actions