CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4158  CVE-2001-1354  Candidate  NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | NOOP(4) Cox, Foat, Green, Wall    View
4161  CVE-2001-1357  Candidate  Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Alderson> Given the fact that there is limited information concerning | these "multiple" vulnerabilities mixed with the importance of time. It | appears that the information obtained so far is as sepcific as its going to | get. | Frech> XF:phpmychat-weak-input(9831)  View
4162  CVE-2001-1358  Candidate  Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Alderson> We should be ready to break this out into more seperate | Candidates should more information come to light on this. | Frech> XF:phpmychat-weak-input(9831)  View
4165  CVE-2001-1361  Candidate  Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:twig-mailto(9871)  View
4164  CVE-2001-1360  Candidate  Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(2) Cox, Frech | NOOP(2) Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> I"m not sure how to vote on this, I did the research and read | the changlog and it appears that the issue you mention here has not | been fixed at all; merely documented as of sane version 1.0.5 | | Change description based on the information in the Sane tarball; note that | this affects all versions to date and is not fixed. | | ---cut--- | | - Security problems with pnm | If the pnm backend is installed and saned is used to allow users on | remote computers to scan on the local machine, pnm files can be read by | the remote user. This is limited to the files saned can access (usually | it"s running as user "sane"). All pnm files can be read if saned runs | as root which isn"t recommended anyway. The pnm backend is disabled | by default. If you want to use it, enable it with configure (see | configure --help for details). Be sure that only trusted users can | access the pnm backend over saned. | | ---cut--- | Frech> XF:sane-prm-read-files(9853)  View

Page 893 of 20943, showing 5 records out of 104715 total, starting on record 4461, ending on 4465

Actions