CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4326  CVE-2001-1526  Candidate  Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.  Assigned (20050714)  None (candidate not yet proposed)    View
4327  CVE-2001-1527  Candidate  easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.  Assigned (20050714)  None (candidate not yet proposed)    View
4328  CVE-2001-1528  Candidate  AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.  Assigned (20050714)  None (candidate not yet proposed)    View
4329  CVE-2001-1529  Candidate  Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.  Assigned (20050714)  None (candidate not yet proposed)    View
4330  CVE-2001-1530  Candidate  run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 866 of 20943, showing 5 records out of 104715 total, starting on record 4326, ending on 4330

Actions