CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4266 | CVE-2001-1463 | Candidate | The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4267 | CVE-2001-1464 | Candidate | Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4268 | CVE-2001-1465 | Candidate | SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4269 | CVE-2001-1466 | Candidate | Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4270 | CVE-2001-1467 | Candidate | mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks. | Assigned (20050421) | None (candidate not yet proposed) | View |
Page 854 of 20943, showing 5 records out of 104715 total, starting on record 4266, ending on 4270