CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6873  CVE-2003-0044  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.  Modified (20071121)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | REVIEWING(1) Jones  Jones> [JHJ] XSS really "execute arbitrary web script"? | CHANGE> [Cox changed vote from NOOP to MODIFY] | Cox> "Agree with Jones, wording on effect of a XSS could be better" | Christey> I"ve been trying to devise reasonable-but-short wordings for | XSS issues and the terminology just isn"t quite there yet. This | description is clearly a failed wording, however :-)  View
6876  CVE-2003-0047  Candidate  SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.  Modified (20071121)  ACCEPT(2) Baker, Stracener | NOOP(4) Cole, Cox, Green, Wall  Green> MULTIPLE VENDORS INVOLVED | Stracener> I"m going to go with this because at least two of the affected vendors acknowledged a fix in the original advisory.  View
186  CVE-1999-0186  Candidate  In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.  Modified (20071119)  ACCEPT(2) Baker, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> Change XF:snmp-backdoor-access to XF:sol-hidden-commstr | Add ISS:Hidden Community String in SNMP Implementation | Christey> What is the proper level of abstraction to use here? Should | we have a separate entry for each different default community | string? See: | http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and | http://cve.mitre.org/Board_Sponsors/archives/msg00250.html | http://cve.mitre.org/Board_Sponsors/archives/msg00251.html | | Until the associated content decisions have been approved | by the Editorial Board, this candidate cannot be accepted | for inclusion in CVE. | Christey> ADDREF BID:177 | Christey> ISS:19981102 Hidden community string in SNMP implementation | http://xforce.iss.net/alerts/advise11.php | | Change description to include "hidden" | Christey> XF:snmp-backdoor-access is missing.  View
1627  CVE-2000-0049  Candidate  Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.  Modified (20071115)  ACCEPT(2) Cole, Wall | MODIFY(2) Baker, Frech | REVIEWING(1) Christey  Frech> XF:winamp-playlist-bo | Christey> This may have been discovered earlier in: | BUGTRAQ:19990512 Buffer overflow in WinAMP 2.x | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92662988700367&w=2 | See the following for possible confirmation: | URL:http://www.winamp.com/getwinamp/newfeatures.jhtml | Wall> This vulnerability has been seen in several versions of Winamp and part of ISS | X-Force | and SecuriTeam vulnerability checks. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> The old confirm url doesn"t work any more... I am not sure where we can get the old changelog/error list.  View
3537  CVE-2001-0729  Candidate  Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.  Modified (20071115)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Christey> The initial description originally stated that this was a | denial of service, but it"s really a directory listing | problem. I changed the description accordingly. | Frech> XF:apache-slash-directory-listing(6921) | Christey> XF:apache-slash-directory-listing(6921) is identifying a | different issue that has not had a CAN assigned yet. | Christey> SGI:20020301-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View

Page 457 of 20943, showing 5 records out of 104715 total, starting on record 2281, ending on 2285

Actions