CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4316  CVE-2001-1516  Candidate  Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews.  Assigned (20050714)  None (candidate not yet proposed)    View
4317  CVE-2001-1517  Candidate  ** DISPUTED ** RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information.  Assigned (20050714)  None (candidate not yet proposed)    View
4318  CVE-2001-1518  Candidate  RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.  Assigned (20050714)  None (candidate not yet proposed)    View
4319  CVE-2001-1519  Candidate  ** DISPUTED ** RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it.  Assigned (20050714)  None (candidate not yet proposed)    View
4320  CVE-2001-1520  Candidate  Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 864 of 20943, showing 5 records out of 104715 total, starting on record 4316, ending on 4320

Actions