CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5942  CVE-2002-1558  Candidate  Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Jones    View
5907  CVE-2002-1523  Candidate  Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) .. (dot-dot backslash) sequences.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall    View
6875  CVE-2003-0046  Candidate  AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.  Modified (20080207)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  Green> PRODUCT ANNOUNCEMENT CONTAINS VENDOR ACKNOWLEDGEMENT  View
6878  CVE-2003-0049  Candidate  Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.  Modified (20071022)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  Baker> Realizing they have acknowledged the problem, and provided a fix by allowing the administrator to select whether or not this is allowed, | I am not sure this should really be a vulnerability. If you are the administrator on a system, there are other ways I can become a user | on a system. The fact that you are the administrator (root) you can do almost anything to the system you want, including accessing files | and programs that belong to other users. From a security standpoint, if the system gets "hacked" and the administrator account is compromised, | how big of an issue is it really that the administrator can now access regular user accounts with the administrator password? I am not sure this | should really be a vulnerability. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]  View
5613  CVE-2002-1229  Candidate  Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.  Modified (20050313)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall    View

Page 934 of 20943, showing 5 records out of 104715 total, starting on record 4666, ending on 4670

Actions