CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6331 | CVE-2002-1949 | Candidate | The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6332 | CVE-2002-1950 | Candidate | Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6333 | CVE-2002-1951 | Candidate | Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6334 | CVE-2002-1952 | Candidate | phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6335 | CVE-2002-1953 | Candidate | Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy. | Assigned (20050629) | None (candidate not yet proposed) | View |
Page 1267 of 20943, showing 5 records out of 104715 total, starting on record 6331, ending on 6335