CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4672 | CVE-2002-0280 | Candidate | Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> May have been "rediscovered" by VulnWatch Mailing List, Wed | Jul 24 2002 - 11:05:00 CDT, "Remote hole in Codeblue log scanner" at | http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0037.html. | If these are the same issue, then v5 also contains this security | issue. | View |
4673 | CVE-2002-0281 | Candidate | Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php. | Modified (20050710) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:dcpportal-userupdate-css(8197) | View |
4676 | CVE-2002-0284 | Candidate | Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:winamp-wma-pathname-disclosure(10030) | View |
4678 | CVE-2002-0286 | Candidate | The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user. | Modified (20050526) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:sitenews-getpassword-add-users(8181) | CONFIRM:http://www.securitytracker.com/alerts/2002/Feb/100349 | 8.html | View |
4680 | CVE-2002-0288 | Candidate | Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:phusion-dot-directoy-traversal(8212) | View |
Page 1150 of 20943, showing 5 records out of 104715 total, starting on record 5746, ending on 5750