CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8594  CVE-2004-0166  Candidate  Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."  Modified (20050510)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
3477  CVE-2001-0669  Candidate  Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.  Modified (20050510)  ACCEPT(4) Armstrong, Baker, Balinsky, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:iis-unicode-encoding-detected(6994) | XF:iis-unicode-wide-encoding(6995)  View
5033  CVE-2002-0643  Candidate  The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."  Modified (20050510)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Wall> There may be a 4th type - clear-text passwords, which may be found in | other setup.iss files. | Christey> XF:mssql-insecure-password-storage(9524) | URL:http://www.iss.net/security_center/static/9524.php | BID:5203 | URL:http://www.securityfocus.com/bid/5203 | Frech> XF:mssql-insecure-password-storage(9524)  View
4018  CVE-2001-1214  Candidate  manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.  Modified (20050510)  ACCEPT(1) Frech | NOOP(6) Christey, Cole, Foat, Green, Wall, Ziese  Christey> I can"t find anything about "Marcus S. Xenakis" on the web at | all, except for vulnerability reports. | CHANGE> [Green changed vote from ACCEPT to NOOP] | Green> The more I looked again today the more circular the references | were getting. And there"s no single pointer to a Marcus | Xenakis site. So, I"ll have to modify the vote to a NOOP. | Christey> A similar issue is in CVE-2002-0434, but CVE-2002-0434 is for | manual.php.  View
4570  CVE-2002-0177  Candidate  Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client.  Modified (20050510)  ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall  Christey> CALDERA:CSSA-2002-020.0 | Christey> Change "allows" to "allow," and add "as exploited through the | client_login function" (to facilitate matching). | REDHAT:RHSA-2002:063 | Frech> XF:icecast-clientlogin-bo(8741)  View

Page 528 of 20943, showing 5 records out of 104715 total, starting on record 2636, ending on 2640

Actions