CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6507  CVE-2002-2125  Candidate  Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user"s local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.  Assigned (20051116)  None (candidate not yet proposed)    View
6508  CVE-2002-2126  Candidate  restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.  Assigned (20051116)  None (candidate not yet proposed)    View
6509  CVE-2002-2127  Candidate  Integrity Protection Driver (IPD) 1.2 and earlier blocks access to DevicePhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.  Assigned (20051116)  None (candidate not yet proposed)    View
6510  CVE-2002-2128  Candidate  editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter.  Assigned (20051116)  None (candidate not yet proposed)    View
6511  CVE-2002-2129  Candidate  Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.  Assigned (20051116)  None (candidate not yet proposed)    View

Page 18718 of 20943, showing 5 records out of 104715 total, starting on record 93586, ending on 93590

Actions