CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3946  CVE-2001-1142  Candidate  ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges.  Proposed (20020315)  ACCEPT(2) Baker, Frech | NOOP(7) Armstrong, Christey, Cole, Foat, Green, Wall, Ziese  Christey> In an e-mail response, the vendor stated that they were | not a crypto expert and were using their own home-grown | crypto. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | Baker> I received an email from Artchil Gogava, of Argosoft, author | of the program in question. I think this is sufficient verification | that the problem is probably as identified. He states he is not an | encryption expert, and that he invented his own encryption mechanism | for this. Need I say more? | | >>>EMAIL<<< | ///// | Subject: Re: Encryption in ArgoSoft FTP Server | Date: Thu, 9 May 2002 15:14:29 -0400 | From: "Artchil Gogava" <archie@argosoft.com> | To: "David Baker" <bakerd@mitre.org> | References: 1 | | Hello David, | | lnk problem, described in the document, has been fixed ages ago, and it does | not present in 1.2.2.2. As of password encryption. I am not an encryption | expert. I am using a method invented by myself, and I am sure that whatever | I do, someone, who has spare time to play around with it, will find the | method to decrypt it. | | Archie  View
3947  CVE-2001-1143  Candidate  IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.  Proposed (20020315)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Foat, Green, Wall | REVIEWING(1) Ziese  Ziese> HAS ANYONE BEEN ABLE TO REPRODUCE THIS?  View
3948  CVE-2001-1144  Entry  Directory traversal vulnerability in McAfee ASaP VirusScan agent 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.        View
3949  CVE-2001-1145  Entry  fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.        View
3950  CVE-2001-1146  Entry  AllCommerce with debugging enabled in EnGarde Secure Linux 1.0.1 creates temporary files with predictable names, which allows local users to modify files via a symlink attack.        View

Page 790 of 20943, showing 5 records out of 104715 total, starting on record 3946, ending on 3950

Actions