CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6331  CVE-2002-1949  Candidate  The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.  Assigned (20050629)  None (candidate not yet proposed)    View
6332  CVE-2002-1950  Candidate  Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.  Assigned (20050629)  None (candidate not yet proposed)    View
6333  CVE-2002-1951  Candidate  Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories.  Assigned (20050629)  None (candidate not yet proposed)    View
6334  CVE-2002-1952  Candidate  phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable.  Assigned (20050629)  None (candidate not yet proposed)    View
6335  CVE-2002-1953  Candidate  Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 1267 of 20943, showing 5 records out of 104715 total, starting on record 6331, ending on 6335

Actions