CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5113 | CVE-2002-0723 | Candidate | Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag." | Modified (20030324-01) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> Need to verify with Microsoft that this is: | BUGTRAQ:20020710 IE allows universal Cross Domain Scripting (TL#003) | URL:http://www.securityfocus.com/archive/1/281367 | MISC:http://www.PivX.com/larholm/adv/TL003/ | BUGTRAQ:20020710 Exploit: TL003/Dot Bug = Reading Non-Parsable Files | URL:http://www.securityfocus.com/archive/1/281660 | Frech> XF:ie-object-scripting(9537) | View |
5114 | CVE-2002-0724 | Candidate | Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service". | Modified (20061101) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> XF:win-smb-packet-bo(9933) | URL:http://www.iss.net/security_center/static/9933.php | BID:5556 | URL:http://www.securityfocus.com/bid/5556 | Frech> XF:win-smb-packet-bo(9933) | View |
3868 | CVE-2001-1064 | Candidate | Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Frech, Green | NOOP(2) Foat, Wall | View | |
3869 | CVE-2001-1065 | Candidate | Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Frech, Green | NOOP(2) Foat, Wall | View | |
3881 | CVE-2001-1077 | Candidate | Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Frech, Green | NOOP(2) Foat, Wall | View |
Page 1060 of 20943, showing 5 records out of 104715 total, starting on record 5296, ending on 5300