CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4095  CVE-2001-1291  Entry  The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.        View
5119  CVE-2002-0729  Entry  Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.        View
5375  CVE-2002-0987  Entry  X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.        View
4814  CVE-2002-0422  Candidate  IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.  Modified (20070919)  ACCEPT(1) Alderson | MODIFY(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:iis-request-ip-disclosure(8385)  View
4800  CVE-2002-0408  Candidate  htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.  Proposed (20020611)  ACCEPT(1) Alderson | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:lotus-domino-reveal-information(8160)  View

Page 611 of 20943, showing 5 records out of 104715 total, starting on record 3051, ending on 3055

Actions