CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4687 | CVE-2002-0295 | Candidate | Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Frech> XF:omnipcx-insecure-groups(8227) | REASON: LIKELY | Christey> Acknowledged by Alcatel via email October 4, 2002 | View |
4715 | CVE-2002-0323 | Candidate | comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Frech> XF:netware-webserver-directory-traversal(7726) | Christey> Need to investigate why some information sources are combining | this with a Novell web server viewcode.asp issue (e.g. the ISS | reference). | | Consider BID:3715 | View |
4733 | CVE-2002-0341 | Candidate | GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Frech> XF:groupwise-arg-path-disclosure(8311) | Christey> Desc: "... which leaks the pathname in an error message." | View |
4662 | CVE-2002-0270 | Candidate | Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | REJECT(1) Armstrong | Frech> XF:ie-opera-contenttype-css(8218) | Christey> BID:4098 | URL:http://www.securityfocus.com/bid/4098 | View |
3393 | CVE-2001-0580 | Candidate | Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection. | Proposed (20010727) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop | Christey> BID:2700 | URL:http://www.securityfocus.com/bid/2700 | Christey> XF:vdns-default-closed-dos(6507) | Frech> XF:vdns-default-closed-dos(6507) | There is a 2.0 version at | http://html.hughestech.com/index.html, but I could not find any | mention of fixes. | View |
Page 1152 of 20943, showing 5 records out of 104715 total, starting on record 5756, ending on 5760