CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5126 | CVE-2002-0736 | Entry | Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. | View | |||
5127 | CVE-2002-0737 | Entry | Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character. | View | |||
5128 | CVE-2002-0738 | Entry | MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3) using "&={script}" syntax. | View | |||
5129 | CVE-2002-0739 | Candidate | Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page. | Proposed (20020726) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
5130 | CVE-2002-0740 | Candidate | Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument. | Proposed (20020726) | ACCEPT(1) Cox | NOOP(4) Armstrong, Cole, Foat, Wall | View |
Page 1026 of 20943, showing 5 records out of 104715 total, starting on record 5126, ending on 5130