CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4181 | CVE-2001-1377 | Candidate | Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2. | Proposed (20020611) | ACCEPT(5) Alderson, Cole, Cox, Frech, Green | NOOP(2) Foat, Wall | View | |
5272 | CVE-2002-0882 | Candidate | The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script. | Proposed (20020830) | ACCEPT(5) Alderson, Cole, Foat, Frech, Jones | NOOP(2) Armstrong, Cox | RECAST(1) Baker | View | |
7419 | CVE-2003-0592 | Candidate | Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. | Modified (20061101) | ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Cox | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Cox> Addref: REDHAT:RHSA-2004:075 | Balinsky> Acknowledgement links already in References. | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | View |
7421 | CVE-2003-0594 | Candidate | Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. | Modified (20100819) | ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Cox | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Christey> REDHAT:RHSA-2004:112 | URL:http://www.redhat.com/support/errata/RHSA-2004-112.html | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Cox> Addref: REDHAT:RHSA-2004:112 | Christey> REDHAT:RHSA-2004:110 | URL:http://www.redhat.com/support/errata/RHSA-2004-110.html | Balinsky> Link in References. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | Christey> HP:SSRT4722 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108448379429944&w=2 | Christey> FEDORA:FLSA:2089 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=109900315219363&w=2 | View |
7340 | CVE-2003-0513 | Candidate | Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. | Proposed (20040318) | ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Green | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(2) Christey, Wall | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | View |
Page 1052 of 20943, showing 5 records out of 104715 total, starting on record 5256, ending on 5260