CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6135  CVE-2002-1753  Candidate  csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.  Assigned (20050621)  None (candidate not yet proposed)    View
6136  CVE-2002-1754  Candidate  Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.  Assigned (20050621)  None (candidate not yet proposed)    View
6137  CVE-2002-1755  Candidate  tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.  Assigned (20050621)  None (candidate not yet proposed)    View
6138  CVE-2002-1756  Candidate  ACDSee 4.0 allows remote attackers to cause a denial of service (crash) via an .ais file with a long file description field, which is not properly handled when the file properties of the file are viewed.  Assigned (20050621)  None (candidate not yet proposed)    View
6139  CVE-2002-1757  Candidate  PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms".  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19270 of 20943, showing 5 records out of 104715 total, starting on record 96346, ending on 96350

Actions