CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3906 | CVE-2001-1102 | Candidate | Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(6) Armstrong, Christey, Cole, Foat, Wall, Ziese | Christey> NOTE: CVE-2001-1171 was discovered to be a duplicate of this | issue. Use this candidate (CVE-2001-1102) instead of the | other one. | View |
3907 | CVE-2001-1103 | Entry | FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands. | View | |||
3908 | CVE-2001-1104 | Candidate | SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions. | Proposed (20020315) | ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Green, Wall, Ziese | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:tcp-seq-predict(139) | View |
3909 | CVE-2001-1105 | Candidate | RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure. | Proposed (20020315) | ACCEPT(6) Armstrong, Baker, Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall | View | |
3910 | CVE-2001-1106 | Entry | The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure. | View |
Page 782 of 20943, showing 5 records out of 104715 total, starting on record 3906, ending on 3910