CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5126  CVE-2002-0736  Entry  Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.        View
5127  CVE-2002-0737  Entry  Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character.        View
5128  CVE-2002-0738  Entry  MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3) using "&={script}" syntax.        View
5129  CVE-2002-0739  Candidate  Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5130  CVE-2002-0740  Candidate  Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.  Proposed (20020726)  ACCEPT(1) Cox | NOOP(4) Armstrong, Cole, Foat, Wall    View

Page 1026 of 20943, showing 5 records out of 104715 total, starting on record 5126, ending on 5130

Actions