CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3704 | CVE-2001-0898 | Candidate | Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript that uses setTimeout to (1) access data after a new window to the domain has been opened or (2) access data via about:cache. | Modified (20050703) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:opera-java-cross-site(7567) | Christey> XF:opera-java-cross-site(7567) | URL:http://www.iss.net/security_center/static/7567.php | BID:3553 | URL:http://www.securityfocus.com/bid/3553 | | Some people are calling this XSS, but is it? | View |
3565 | CVE-2001-0758 | Candidate | Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command. | Proposed (20011012) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:shambala-ftp-cwd-directory-traversal(7418) | Christey> Other .. problems were found in 4.5 as described in: | BUGTRAQ:20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0282.html | CD:SF-LOC might suggest merging these two. (I"m working | on creating a CAN for the newer discovery). | View |
3573 | CVE-2001-0766 | Candidate | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache"s filters. | Proposed (20011012) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Foat, Wall | Frech> XF:macos-apache-file-disclosure(6687) | Christey> CERT-VN:VU#439395 | URL:http://www.kb.cert.org/vuls/id/439395 | View |
4878 | CVE-2002-0486 | Candidate | Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges. | Proposed (20020611) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:xpede-password-weak-encryption(8614) | View |
4884 | CVE-2002-0492 | Candidate | dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter. | Proposed (20020611) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:dscshop-cgi-delete-setup(9854) | View |
Page 1148 of 20943, showing 5 records out of 104715 total, starting on record 5736, ending on 5740