CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2265  CVE-2000-0689  Candidate  Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.  Modified (20061027)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:account-manager-overwrite-password | In description, you probably want to indicate both Account Manager LITE and PRO. | Because CONFIRM redirects, you may want to verify and normalize to http://www.cgiscriptcenter.com/acctman/index2.html. | Christey> XF:account-manager-overwrite-password | http://xforce.iss.net/static/5125.php | Frech> XF:account-manager-overwrite-password(5125)  View
2298  CVE-2000-0722  Candidate  Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:linux-update-race-condition | Frech> XF:gnome-installer-overwrite-configuration(5129)  View
2299  CVE-2000-0723  Candidate  Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:gnome-installer-overwrite-configuration(5129) | Frech> XF:gnome-installer-overwrite-configuration(5129)  View
2300  CVE-2000-0724  Candidate  The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:go-gnome-preinstaller-symlink(5161) | Frech> XF:go-gnome-preinstaller-symlink(5161)  View
2201  CVE-2000-0625  Candidate  NetZero 3.0 and earlier uses weak encryption for storing a user"s login information, which allows a local user to decrypt the password.  Proposed (20000803)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall  Frech> XF:zeroport-weak-encryption(4963)  View

Page 844 of 20943, showing 5 records out of 104715 total, starting on record 4216, ending on 4220

Actions