CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5060  CVE-2002-0670  Candidate  The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.  Modified (20050610)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:pingtel-xpressa-plaintext-passwords(9565)  View
5070  CVE-2002-0680  Candidate  Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.  Proposed (20020726)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:goahead-directory-traversal(6046)  View
3296  CVE-2001-0479  Candidate  Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.  Proposed (20010524)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Balinsky, Cole, Renaud, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:phppgadmin-sqlphp-include-file(6484) | Balinsky> Advisory site no longer exists. There is not enough detail in the advisory, and the vendor does not acknowledge.  View
2905  CVE-2001-0084  Candidate  GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.  Proposed (20010202)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Christey, Cole, Prosser, Wall, Ziese  Frech> XF:gtk-module-execute-code(5832) | Christey> XF:gtk-module-execute-code | URL:http://xforce.iss.net/static/5832.php | Christey> TURBO:TLSA2001026 | URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000440.html  View
3630  CVE-2001-0824  Candidate  Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.  Proposed (20011122)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall  Frech> XF:java-servlet-crosssite-scripting(6793) | This issue is associated with multiple operating | environments. | Christey> CERT-VN:VU#560659 | URL:http://www.kb.cert.org/vuls/id/560659 | MISC:http://www.kb.cert.org/vuls/id/JARL-4YZKLU  View

Page 631 of 20943, showing 5 records out of 104715 total, starting on record 3151, ending on 3155

Actions