CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
452 | CVE-1999-0453 | Candidate | An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). | Modified (20040512-02) | ACCEPT(2) Baker, Balinsky | MODIFY(1) Frech | NOOP(2) Northcutt, Wall | REVIEWING(1) Christey | Frech> XF:cisco-ident(2289) | ADDREF BUGTRAQ:19990118 Remote Cisco Identification | In description, probably better to use "Cisco" as product/company name. | Balinsky> CiscoSecure IDS has a signature for this...ID 3602 Cisco IOS Identity. | Christey> There may be a slight abstraction problem here, e.g. look | at the candidate for queso/nmap; also see followup Bugtraq post | from "Basement Research" on 19990120 which says that there are | many other features in Cisco products that allow remote | identification. | Christey> fix typo: "Dicsovery" | View |
3309 | CVE-2001-0492 | Candidate | Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3. | Modified (20030619-02) | ACCEPT(4) Baker, Balinsky, Cole, Oliver | MODIFY(1) Frech | NOOP(4) Christey, Wall, Williams, Ziese | CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT] | Balinsky> Vendor acknowledged the problem in a personal communication. | Frech> XF:netcruiser-server-path-disclosure(6468) | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> Fix typo (accidental URL insertion) in XF reference | View |
982 | CVE-1999-1002 | Candidate | Netscape Navigator uses weak encryption for storing a user"s Netscape mail password. | Modified (20030619-01) | ACCEPT(4) Baker, Cole, Stracener, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:netscape-mail-encryption(3921) | Christey> CHANGEREF make the RCA URL a "MISC" reference | View |
5245 | CVE-2002-0855 | Candidate | Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber"s list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature. | Modified (20030325-01) | ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat | Cox> ADDREF:REDHAT:RHSA-2002:181 | Frech> XF:mailman-subscription-option-xss(9985) | Christey> Add to desc: "via the (1) adminpw or (2) info parameters to | the ml-name feature. | ADDREF CONECTIVA:CLA-2002:522 | | It"s not clear whether DEBIAN:DSA-147-2 addresses this issue | in addition to, or instead of, CVE-2002-0388 | Christey> BID:5298 | | Debian (Joey) has confirmed that DSA-147 also addresses this | issue. | View |
5332 | CVE-2002-0944 | Candidate | Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program. | Modified (20030325-01) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Christey, Cox, Foat, Wall | Christey> On February 19, 2003, DeepMetrix confirmed via email that this | bug has been corrected in LiveStats 6.2.2. | | CONFIRM:http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp | | As of February 19, this URL only mentions the User-Agent bug, | but the vendor again confirmed via email that the referrer is | also addressed. | View |
Page 545 of 20943, showing 5 records out of 104715 total, starting on record 2721, ending on 2725