CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3704  CVE-2001-0898  Candidate  Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript that uses setTimeout to (1) access data after a new window to the domain has been opened or (2) access data via about:cache.  Modified (20050703)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Frech> XF:opera-java-cross-site(7567) | Christey> XF:opera-java-cross-site(7567) | URL:http://www.iss.net/security_center/static/7567.php | BID:3553 | URL:http://www.securityfocus.com/bid/3553 | | Some people are calling this XSS, but is it?  View
3565  CVE-2001-0758  Candidate  Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command.  Proposed (20011012)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Frech> XF:shambala-ftp-cwd-directory-traversal(7418) | Christey> Other .. problems were found in 4.5 as described in: | BUGTRAQ:20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0282.html | CD:SF-LOC might suggest merging these two. (I"m working | on creating a CAN for the newer discovery).  View
3573  CVE-2001-0766  Candidate  Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache"s filters.  Proposed (20011012)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall  Frech> XF:macos-apache-file-disclosure(6687) | Christey> CERT-VN:VU#439395 | URL:http://www.kb.cert.org/vuls/id/439395  View
4878  CVE-2002-0486  Candidate  Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.  Proposed (20020611)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:xpede-password-weak-encryption(8614)  View
4884  CVE-2002-0492  Candidate  dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.  Proposed (20020611)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:dscshop-cgi-delete-setup(9854)  View

Page 1148 of 20943, showing 5 records out of 104715 total, starting on record 5736, ending on 5740

Actions