CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2919  CVE-2001-0098  Candidate  Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2924  CVE-2001-0103  Candidate  CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.  Modified (20071018)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2925  CVE-2001-0104  Candidate  MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
3194  CVE-2001-0376  Candidate  SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys. This allows a remote attacker to brute force attack the pre-shared keys with significantly less resources than if the full 128 byte IKE pre-shared keys were used.  Proposed (20010524)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
3074  CVE-2001-0253  Candidate  Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.  Modified (20050509)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop    View

Page 693 of 20943, showing 5 records out of 104715 total, starting on record 3461, ending on 3465

Actions