CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4860 | CVE-2002-0468 | Candidate | Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files. | Proposed (20020611) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(3) Cox, Foat, Wall | View | |
3927 | CVE-2001-1123 | Candidate | Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID. | Proposed (20020315) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Armstrong, Foat, Wall, Ziese | View | |
5332 | CVE-2002-0944 | Candidate | Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program. | Modified (20030325-01) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Christey, Cox, Foat, Wall | Christey> On February 19, 2003, DeepMetrix confirmed via email that this | bug has been corrected in LiveStats 6.2.2. | | CONFIRM:http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp | | As of February 19, this URL only mentions the User-Agent bug, | but the vendor again confirmed via email that the referrer is | also addressed. | View |
2519 | CVE-2000-0950 | Candidate | Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name. | Proposed (20001129) | ACCEPT(4) Baker, Cole, Frech, Mell | NOOP(1) Renaud | REVIEWING(1) Christey | Christey> I thought I saw some mailing list that questioned whether this | problem was only a DoS... | View |
4736 | CVE-2002-0344 | Candidate | Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server. | Proposed (20020502) | ACCEPT(4) Baker, Cole, Frech, Prosser | NOOP(3) Cox, Foat, Wall | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2002.02.28a.html | View |
Page 1022 of 20943, showing 5 records out of 104715 total, starting on record 5106, ending on 5110