CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5248  CVE-2002-0858  Candidate  catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges.  Modified (20071101)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:oracle-catsnmp-default-account(9932)  View
5537  CVE-2002-1150  Candidate  The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and canceling out of the resulting user confirmation prompts, such as when the remote user is editing a document.  Modified (20071101)  ACCEPT(1) Baker | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5027  CVE-2002-0637  Candidate  InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express.  Modified (20071101)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> BID:5259 | URL:http://online.securityfocus.com/bid/5259 | CONFIRM:http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionId=11948 | | According to Axel Pettinger, Solaris 3.7 build 1070 | is affected by the "boundary space (trailing)" and "Boundary | Space (prefix)" problems, but not the content-type or transfer | encoding issues. That version clearly has some overlap with | this issue, but since a different build and version number are | affected, perhaps a separate candidate needs to be created. | More information on that issue is at: | http://solutionbank.antivirus.com/solutions/solutiondetail.asp?solutionID=12142 | | Baker> http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionID=11948 | Frech> XF:interscan-viruswall-protection-bypass(9464)  View
5044  CVE-2002-0654  Candidate  Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.  Modified (20071101)  ACCEPT(4) Armstrong, Baker, Cox, Foat | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Wall  Frech> XF:apache-cgi-path-disclosure(9876) | XF:apache-var-path-disclosure(9875) | In description, correct product names to OS/2 and NetWare.  View
5575  CVE-2002-1191  Candidate  The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.  Modified (20071101)  ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall    View

Page 467 of 20943, showing 5 records out of 104715 total, starting on record 2331, ending on 2335

Actions