CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6873 | CVE-2003-0044 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML. | Modified (20071121) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | REVIEWING(1) Jones | Jones> [JHJ] XSS really "execute arbitrary web script"? | CHANGE> [Cox changed vote from NOOP to MODIFY] | Cox> "Agree with Jones, wording on effect of a XSS could be better" | Christey> I"ve been trying to devise reasonable-but-short wordings for | XSS issues and the terminology just isn"t quite there yet. This | description is clearly a failed wording, however :-) | View |
6876 | CVE-2003-0047 | Candidate | SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials. | Modified (20071121) | ACCEPT(2) Baker, Stracener | NOOP(4) Cole, Cox, Green, Wall | Green> MULTIPLE VENDORS INVOLVED | Stracener> I"m going to go with this because at least two of the affected vendors acknowledged a fix in the original advisory. | View |
186 | CVE-1999-0186 | Candidate | In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters. | Modified (20071119) | ACCEPT(2) Baker, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> Change XF:snmp-backdoor-access to XF:sol-hidden-commstr | Add ISS:Hidden Community String in SNMP Implementation | Christey> What is the proper level of abstraction to use here? Should | we have a separate entry for each different default community | string? See: | http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and | http://cve.mitre.org/Board_Sponsors/archives/msg00250.html | http://cve.mitre.org/Board_Sponsors/archives/msg00251.html | | Until the associated content decisions have been approved | by the Editorial Board, this candidate cannot be accepted | for inclusion in CVE. | Christey> ADDREF BID:177 | Christey> ISS:19981102 Hidden community string in SNMP implementation | http://xforce.iss.net/alerts/advise11.php | | Change description to include "hidden" | Christey> XF:snmp-backdoor-access is missing. | View |
1627 | CVE-2000-0049 | Candidate | Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file. | Modified (20071115) | ACCEPT(2) Cole, Wall | MODIFY(2) Baker, Frech | REVIEWING(1) Christey | Frech> XF:winamp-playlist-bo | Christey> This may have been discovered earlier in: | BUGTRAQ:19990512 Buffer overflow in WinAMP 2.x | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92662988700367&w=2 | See the following for possible confirmation: | URL:http://www.winamp.com/getwinamp/newfeatures.jhtml | Wall> This vulnerability has been seen in several versions of Winamp and part of ISS | X-Force | and SecuriTeam vulnerability checks. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> The old confirm url doesn"t work any more... I am not sure where we can get the old changelog/error list. | View |
3537 | CVE-2001-0729 | Candidate | Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters. | Modified (20071115) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately. | View |
Page 457 of 20943, showing 5 records out of 104715 total, starting on record 2281, ending on 2285