CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5226 | CVE-2002-0836 | Entry | dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts. | View | |||
5227 | CVE-2002-0837 | Candidate | wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") to the wordtrans.php script. | Proposed (20030317) | ACCEPT(4) Armstrong, Cole, Cox, Green | Cox> I believe this to mean "multiple exploit vectors" for the single | vulnerability. The patch to correct this issue was a single line that | would remove any non-alphabetic characters from the "dict" parameter. | View |
5228 | CVE-2002-0838 | Candidate | Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Frech, Wall | MODIFY(1) Cox | NOOP(1) Christey | Cox> Addref: RHSA-2002:211 | Christey> GENTOO:GLSA-200408-10 | URL:http://www.gentoo.org/security/en/glsa/glsa-200408-10.xml | View |
5229 | CVE-2002-0839 | Candidate | The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard. | Modified (20110830) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | Christey> CONFIRM:http://www.info.apple.com/usen/security/security_updates.html | Cox> Addref: RHSA-2002:251 | Addref: RHSA-2002:248 | Addref: RHSA-2002:244 | Addref: RHSA-2002:243 | Addref: RHSA-2002:222 | Change Apache Week ref to: http://www.apacheweek.com/issues/02-10-04#security | Christey> SGI:20021105-02-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20021105-02-I | View |
5230 | CVE-2002-0840 | Entry | Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157. | View |
Page 1046 of 20943, showing 5 records out of 104715 total, starting on record 5226, ending on 5230