CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4326 | CVE-2001-1526 | Candidate | Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4327 | CVE-2001-1527 | Candidate | easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4328 | CVE-2001-1528 | Candidate | AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4329 | CVE-2001-1529 | Candidate | Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4330 | CVE-2001-1530 | Candidate | run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 866 of 20943, showing 5 records out of 104715 total, starting on record 4326, ending on 4330