CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4266  CVE-2001-1463  Candidate  The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.  Assigned (20050421)  None (candidate not yet proposed)    View
4267  CVE-2001-1464  Candidate  Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.  Assigned (20050421)  None (candidate not yet proposed)    View
4268  CVE-2001-1465  Candidate  SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.  Assigned (20050421)  None (candidate not yet proposed)    View
4269  CVE-2001-1466  Candidate  Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.  Assigned (20050421)  None (candidate not yet proposed)    View
4270  CVE-2001-1467  Candidate  mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.  Assigned (20050421)  None (candidate not yet proposed)    View

Page 854 of 20943, showing 5 records out of 104715 total, starting on record 4266, ending on 4270

Actions