CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6335  CVE-2002-1953  Candidate  Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy.  Assigned (20050629)  None (candidate not yet proposed)    View
6336  CVE-2002-1954  Candidate  Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.  Assigned (20050629)  None (candidate not yet proposed)    View
6337  CVE-2002-1955  Candidate  Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack.  Assigned (20050629)  None (candidate not yet proposed)    View
6338  CVE-2002-1956  Candidate  ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files.  Assigned (20050629)  None (candidate not yet proposed)    View
6339  CVE-2002-1957  Candidate  Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 19223 of 20943, showing 5 records out of 104715 total, starting on record 96111, ending on 96115

Actions