CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5248 | CVE-2002-0858 | Candidate | catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges. | Modified (20071101) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:oracle-catsnmp-default-account(9932) | View |
5537 | CVE-2002-1150 | Candidate | The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and canceling out of the resulting user confirmation prompts, such as when the remote user is editing a document. | Modified (20071101) | ACCEPT(1) Baker | NOOP(2) Cole, Cox | REVIEWING(1) Wall | View | |
5027 | CVE-2002-0637 | Candidate | InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express. | Modified (20071101) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> BID:5259 | URL:http://online.securityfocus.com/bid/5259 | CONFIRM:http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionId=11948 | | According to Axel Pettinger, Solaris 3.7 build 1070 | is affected by the "boundary space (trailing)" and "Boundary | Space (prefix)" problems, but not the content-type or transfer | encoding issues. That version clearly has some overlap with | this issue, but since a different build and version number are | affected, perhaps a separate candidate needs to be created. | More information on that issue is at: | http://solutionbank.antivirus.com/solutions/solutiondetail.asp?solutionID=12142 | | Baker> http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionID=11948 | Frech> XF:interscan-viruswall-protection-bypass(9464) | View |
5044 | CVE-2002-0654 | Candidate | Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked. | Modified (20071101) | ACCEPT(4) Armstrong, Baker, Cox, Foat | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Wall | Frech> XF:apache-cgi-path-disclosure(9876) | XF:apache-var-path-disclosure(9875) | In description, correct product names to OS/2 and NetWare. | View |
5575 | CVE-2002-1191 | Candidate | The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001. | Modified (20071101) | ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | View |
Page 467 of 20943, showing 5 records out of 104715 total, starting on record 2331, ending on 2335