CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4316 | CVE-2001-1516 | Candidate | Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4317 | CVE-2001-1517 | Candidate | ** DISPUTED ** RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4318 | CVE-2001-1518 | Candidate | RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4319 | CVE-2001-1519 | Candidate | ** DISPUTED ** RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4320 | CVE-2001-1520 | Candidate | Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 864 of 20943, showing 5 records out of 104715 total, starting on record 4316, ending on 4320