CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5141  CVE-2002-0751  Candidate  CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form-results parameters.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5142  CVE-2002-0752  Candidate  CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackers to obtain sensitive information by directly accessing the file.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5143  CVE-2002-0753  Candidate  Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5144  CVE-2002-0754  Entry  Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.        View
5145  CVE-2002-0755  Entry  Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, which could allow unauthorized users to execute commands as root.        View

Page 1029 of 20943, showing 5 records out of 104715 total, starting on record 5141, ending on 5145

Actions