CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7850  CVE-2003-1026  Candidate  Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window"s zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."  Assigned (20040107)  None (candidate not yet proposed)    View
7849  CVE-2003-1025  Candidate  Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."  Assigned (20040106)  None (candidate not yet proposed)    View
7848  CVE-2003-1024  Candidate  Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.  Assigned (20040106)  None (candidate not yet proposed)    View
7847  CVE-2003-1023  Candidate  Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.  Assigned (20040105)  NOOP(1) Christey  Christey> CALDERA:CSSA-2004-014.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-014.0.txt  View
7846  CVE-2003-1022  Entry  Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.        View

Page 19374 of 20943, showing 5 records out of 104715 total, starting on record 96866, ending on 96870

Actions