CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4736  CVE-2002-0344  Candidate  Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.  Proposed (20020502)  ACCEPT(4) Baker, Cole, Frech, Prosser | NOOP(3) Cox, Foat, Wall  Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2002.02.28a.html  View
4737  CVE-2002-0345  Candidate  Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServerparams registry key, which could allow an attacker to gain privileges.  Proposed (20020502)  ACCEPT(2) Frech, Prosser | NOOP(4) Cole, Cox, Foat, Wall  Prosser> This was verified and responded to via BugTraq and fixed via | LiveUpdate http://online.securityfocus.com/archive/1/259559  View
4738  CVE-2002-0346  Candidate  Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4739  CVE-2002-0347  Candidate  Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4740  CVE-2002-0348  Candidate  service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 948 of 20943, showing 5 records out of 104715 total, starting on record 4736, ending on 4740

Actions