CVE List

Id CVE No. Status Description Phase Votes Comments Actions
909  CVE-1999-0929  Candidate  Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.  Interim (19991229)  ACCEPT(4) Armstrong, Blake, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker  Frech> XF:novell-webserver-dos(2287)  View
4631  CVE-2002-0239  Candidate  Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.  Modified (20050703)  ACCEPT(4) Armstrong, Cole, Cox, Frech | NOOP(2) Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to ACCEPT]  View
5660  CVE-2002-1276  Candidate  An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.  Modified (20071113)  ACCEPT(4) Armstrong, Cole, Cox, Green    View
5227  CVE-2002-0837  Candidate  wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") to the wordtrans.php script.  Proposed (20030317)  ACCEPT(4) Armstrong, Cole, Cox, Green  Cox> I believe this to mean "multiple exploit vectors" for the single | vulnerability. The patch to correct this issue was a single line that | would remove any non-alphabetic characters from the "dict" parameter.  View
5518  CVE-2002-1131  Candidate  Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.  Proposed (20030317)  ACCEPT(4) Armstrong, Cole, Cox, Green    View

Page 1006 of 20943, showing 5 records out of 104715 total, starting on record 5026, ending on 5030

Actions