CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2776  CVE-2000-1209  Candidate  The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.  Modified (20071113)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Frech> XF:tumbleweed-mms-blank-password(5072) | XF:msde-mssql-default-password(9154) | May overlap with CVE-2000-0772. | Christey> fix desc - "installed with a default password" appears twice.  View
2777  CVE-2000-1210  Entry  Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.        View
2778  CVE-2000-1211  Entry  Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.        View
2779  CVE-2000-1212  Entry  Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.        View
2780  CVE-2000-1213  Candidate  ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping"s exposure to bugs that otherwise would occur at lower privileges.  Proposed (20020830)  ACCEPT(7) Armstrong, Baker, Cole, Cox, Foat, Green, Wall | MODIFY(1) Frech  Frech> XF:iputils-ping-privileges(11090)  View

Page 556 of 20943, showing 5 records out of 104715 total, starting on record 2776, ending on 2780

Actions