CVE List

Id CVE No. Status Description Phase Votes Comments Actions
452  CVE-1999-0453  Candidate  An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).  Modified (20040512-02)  ACCEPT(2) Baker, Balinsky | MODIFY(1) Frech | NOOP(2) Northcutt, Wall | REVIEWING(1) Christey  Frech> XF:cisco-ident(2289) | ADDREF BUGTRAQ:19990118 Remote Cisco Identification | In description, probably better to use "Cisco" as product/company name. | Balinsky> CiscoSecure IDS has a signature for this...ID 3602 Cisco IOS Identity. | Christey> There may be a slight abstraction problem here, e.g. look | at the candidate for queso/nmap; also see followup Bugtraq post | from "Basement Research" on 19990120 which says that there are | many other features in Cisco products that allow remote | identification. | Christey> fix typo: "Dicsovery"  View
3309  CVE-2001-0492  Candidate  Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.  Modified (20030619-02)  ACCEPT(4) Baker, Balinsky, Cole, Oliver | MODIFY(1) Frech | NOOP(4) Christey, Wall, Williams, Ziese  CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT] | Balinsky> Vendor acknowledged the problem in a personal communication. | Frech> XF:netcruiser-server-path-disclosure(6468) | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> Fix typo (accidental URL insertion) in XF reference  View
982  CVE-1999-1002  Candidate  Netscape Navigator uses weak encryption for storing a user"s Netscape mail password.  Modified (20030619-01)  ACCEPT(4) Baker, Cole, Stracener, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:netscape-mail-encryption(3921) | Christey> CHANGEREF make the RCA URL a "MISC" reference  View
5245  CVE-2002-0855  Candidate  Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber"s list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.  Modified (20030325-01)  ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat  Cox> ADDREF:REDHAT:RHSA-2002:181 | Frech> XF:mailman-subscription-option-xss(9985) | Christey> Add to desc: "via the (1) adminpw or (2) info parameters to | the ml-name feature. | ADDREF CONECTIVA:CLA-2002:522 | | It"s not clear whether DEBIAN:DSA-147-2 addresses this issue | in addition to, or instead of, CVE-2002-0388 | Christey> BID:5298 | | Debian (Joey) has confirmed that DSA-147 also addresses this | issue.  View
5332  CVE-2002-0944  Candidate  Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.  Modified (20030325-01)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Christey, Cox, Foat, Wall  Christey> On February 19, 2003, DeepMetrix confirmed via email that this | bug has been corrected in LiveStats 6.2.2. | | CONFIRM:http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp | | As of February 19, this URL only mentions the User-Agent bug, | but the vendor again confirmed via email that the referrer is | also addressed.  View

Page 545 of 20943, showing 5 records out of 104715 total, starting on record 2721, ending on 2725

Actions