CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3451  CVE-2001-0642  Candidate  Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.  Proposed (20010829)  ACCEPT(1) Frech | NOOP(5) Cole, Foat, Stracener, Wall, Ziese    View
3452  CVE-2001-0643  Entry  Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.        View
3453  CVE-2001-0644  Entry  Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server.        View
3454  CVE-2001-0645  Candidate  Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.  Modified (20050510)  ACCEPT(5) Baker, Cole, Frech, Prosser, Ziese | NOOP(2) Foat, Wall  Prosser> Additional Reference | http://www.sarc.com/avcenter/security/Content/2001_05_08.html | Prosser> Add Symantec vendor advisory source | http://securityresponse.symantec.com/avcenter/security/Content/2001_05_08.html  View
3455  CVE-2001-0646  Entry  Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.        View

Page 691 of 20943, showing 5 records out of 104715 total, starting on record 3451, ending on 3455

Actions