CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4687  CVE-2002-0295  Candidate  Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:omnipcx-insecure-groups(8227) | REASON: LIKELY | Christey> Acknowledged by Alcatel via email October 4, 2002  View
4715  CVE-2002-0323  Candidate  comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:netware-webserver-directory-traversal(7726) | Christey> Need to investigate why some information sources are combining | this with a Novell web server viewcode.asp issue (e.g. the ISS | reference). | | Consider BID:3715  View
4733  CVE-2002-0341  Candidate  GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:groupwise-arg-path-disclosure(8311) | Christey> Desc: "... which leaks the pathname in an error message."  View
4662  CVE-2002-0270  Candidate  Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | REJECT(1) Armstrong  Frech> XF:ie-opera-contenttype-css(8218) | Christey> BID:4098 | URL:http://www.securityfocus.com/bid/4098  View
3393  CVE-2001-0580  Candidate  Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.  Proposed (20010727)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Christey> BID:2700 | URL:http://www.securityfocus.com/bid/2700 | Christey> XF:vdns-default-closed-dos(6507) | Frech> XF:vdns-default-closed-dos(6507) | There is a 2.0 version at | http://html.hughestech.com/index.html, but I could not find any | mention of fixes.  View

Page 1152 of 20943, showing 5 records out of 104715 total, starting on record 5756, ending on 5760

Actions