CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2201 | CVE-2000-0625 | Candidate | NetZero 3.0 and earlier uses weak encryption for storing a user"s login information, which allows a local user to decrypt the password. | Proposed (20000803) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | Frech> XF:zeroport-weak-encryption(4963) | View |
2202 | CVE-2000-0626 | Candidate | Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. | Proposed (20000803) | ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey | Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers. | View |
2203 | CVE-2000-0627 | Entry | BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl. | View | |||
2204 | CVE-2000-0628 | Entry | The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files. | View | |||
2205 | CVE-2000-0629 | Candidate | The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet. | Proposed (20000803) | ACCEPT(3) Cole, Dik, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall | Frech> XF:sunjava-webadmin-bbs(5135) | Christey> Need to create/update | Dik> (through internal confirmation) | View |
Page 441 of 20943, showing 5 records out of 104715 total, starting on record 2201, ending on 2205