CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4661  CVE-2002-0269  Candidate  Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:ie-opera-contenttype-css(8218)  View
4150  CVE-2001-1346  Candidate  Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:arcserveit-inetd-tmpfile-symlink(10006) | XF:arcserveit-asagent-tmpfile-symlink(10007)  View
4662  CVE-2002-0270  Candidate  Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | REJECT(1) Armstrong  Frech> XF:ie-opera-contenttype-css(8218) | Christey> BID:4098 | URL:http://www.securityfocus.com/bid/4098  View
4663  CVE-2002-0271  Candidate  Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.  Proposed (20020502)  ACCEPT(1) Cox | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | Frech> XF:gnat-temp-symlink(8178)  View
4152  CVE-2001-1348  Candidate  TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall  Green> Even if vague, there is acknowledgement.  View

Page 132 of 20943, showing 5 records out of 104715 total, starting on record 656, ending on 660

Actions