CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4961  CVE-2002-0570  Candidate  The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | MODIFY(1) Foat | NOOP(2) Cox, Wall  Foat> A local user can not modify the data. The user needs to root the box | first or at least get UNIX permission to write to the encrypted file system. | This is different than being a local user. | CHANGE> [Cox changed vote from REVIEWING to NOOP]  View
4813  CVE-2002-0421  Candidate  IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View
4159  CVE-2001-1355  Candidate  Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4160  CVE-2001-1356  Candidate  NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
5297  CVE-2002-0908  Candidate  Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTPS request.  Proposed (20020830)  ACCEPT(3) Alderson, Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Jones    View

Page 892 of 20943, showing 5 records out of 104715 total, starting on record 4456, ending on 4460

Actions