CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3811  CVE-2001-1007  Candidate  Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:truesync-desktop-devicekeys-bruteforce(8712)  View
3812  CVE-2001-1008  Entry  Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.        View
3813  CVE-2001-1009  Candidate  Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.  Modified (20020817-01)  ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:fetchmail-signed-integer-index(6965)  View
3814  CVE-2001-1010  Entry  Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.        View
3815  CVE-2001-1011  Entry  index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.        View

Page 763 of 20943, showing 5 records out of 104715 total, starting on record 3811, ending on 3815

Actions