CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2201  CVE-2000-0625  Candidate  NetZero 3.0 and earlier uses weak encryption for storing a user"s login information, which allows a local user to decrypt the password.  Proposed (20000803)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall  Frech> XF:zeroport-weak-encryption(4963)  View
2202  CVE-2000-0626  Candidate  Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.  Proposed (20000803)  ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey  Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers.  View
2203  CVE-2000-0627  Entry  BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.        View
2204  CVE-2000-0628  Entry  The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.        View
2205  CVE-2000-0629  Candidate  The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.  Proposed (20000803)  ACCEPT(3) Cole, Dik, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall  Frech> XF:sunjava-webadmin-bbs(5135) | Christey> Need to create/update | Dik> (through internal confirmation)  View

Page 441 of 20943, showing 5 records out of 104715 total, starting on record 2201, ending on 2205

Actions