CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4864  CVE-2002-0472  Candidate  MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall    View
3855  CVE-2001-1051  Candidate  Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3856  CVE-2001-1052  Candidate  Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
4507  CVE-2002-0113  Candidate  EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
4508  CVE-2002-0114  Candidate  EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View

Page 854 of 20943, showing 5 records out of 104715 total, starting on record 4266, ending on 4270

Actions