CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4685  CVE-2002-0293  Candidate  FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root"s .profile file.  Modified (20050527)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:omnipcx-ftp-root-access(8225) | Christey> Acknowledged by Alcatel via email October 4, 2002  View
4688  CVE-2002-0296  Candidate  The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.  Modified (20050527)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:tarantella-tmp-spinning-symlink(8223)  View
4700  CVE-2002-0308  Candidate  admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.  Modified (20050527)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:admentor-asp-gain-access(8245)  View
4702  CVE-2002-0310  Candidate  Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.  Modified (20050527)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:webnews-cgi-default-accounts(8255)  View
4525  CVE-2002-0131  Candidate  ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client"s filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script.  Modified (20050527)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View

Page 522 of 20943, showing 5 records out of 104715 total, starting on record 2606, ending on 2610

Actions