CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7017  CVE-2003-0188  Candidate  lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.  Assigned (20030401)  None (candidate not yet proposed)    View
7018  CVE-2003-0189  Candidate  The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used.  Assigned (20030401)  None (candidate not yet proposed)    View
7019  CVE-2003-0190  Candidate  OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.  Assigned (20030401)  None (candidate not yet proposed)    View
7020  CVE-2003-0192  Candidate  Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.  Assigned (20030401)  None (candidate not yet proposed)    View
7021  CVE-2003-0193  Candidate  msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").  Assigned (20030401)  None (candidate not yet proposed)    View

Page 652 of 20943, showing 5 records out of 104715 total, starting on record 3256, ending on 3260

Actions