CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7160  CVE-2003-0332  Candidate  The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.  Assigned (20030520)  None (candidate not yet proposed)    View
7161  CVE-2003-0333  Candidate  Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.  Assigned (20030521)  None (candidate not yet proposed)    View
7168  CVE-2003-0340  Candidate  Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.  Assigned (20030522)  None (candidate not yet proposed)    View
7169  CVE-2003-0341  Candidate  Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search field.  Assigned (20030522)  None (candidate not yet proposed)    View
7170  CVE-2003-0342  Candidate  BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges.  Assigned (20030522)  None (candidate not yet proposed)    View

Page 681 of 20943, showing 5 records out of 104715 total, starting on record 3401, ending on 3405

Actions