CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6158  CVE-2002-1776  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.  Assigned (20050621)  None (candidate not yet proposed)    View
6159  CVE-2002-1777  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to obtain the file name. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but Norton AntiVirus or the Office plug-in would detect the virus before it is executed.  Assigned (20050621)  None (candidate not yet proposed)    View
6160  CVE-2002-1778  Candidate  Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by using a (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH scan.  Assigned (20050621)  None (candidate not yet proposed)    View
6161  CVE-2002-1779  Candidate  The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).  Assigned (20050621)  None (candidate not yet proposed)    View
6162  CVE-2002-1780  Candidate  BPM Studio Pro 4.2 by ALCATech GmbH includes a webserver that allows a remote attacker to cause a denial of service (crash) by sending a URL request for a MS-DOS device such as con. NOTE: it has been disputed that this and possibly other application-level DOS device issues stem from a bug in Windows, and as such, such applications should not be considered vulnerable themselves.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19240 of 20943, showing 5 records out of 104715 total, starting on record 96196, ending on 96200

Actions