CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4095 | CVE-2001-1291 | Entry | The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing. | View | |||
5119 | CVE-2002-0729 | Entry | Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator. | View | |||
5375 | CVE-2002-0987 | Entry | X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges. | View | |||
4814 | CVE-2002-0422 | Candidate | IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header. | Modified (20070919) | ACCEPT(1) Alderson | MODIFY(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall | Frech> XF:iis-request-ip-disclosure(8385) | View |
4800 | CVE-2002-0408 | Candidate | htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message. | Proposed (20020611) | ACCEPT(1) Alderson | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:lotus-domino-reveal-information(8160) | View |
Page 611 of 20943, showing 5 records out of 104715 total, starting on record 3051, ending on 3055