CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6695 | CVE-2002-2313 | Candidate | Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedded .mhtml file with ActiveX controls that execute a second embedded program, which is processed by Internet Explorer. | Assigned (20071026) | None (candidate not yet proposed) | View | |
6694 | CVE-2002-2312 | Candidate | Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. | Assigned (20071026) | None (candidate not yet proposed) | View | |
6693 | CVE-2002-2311 | Candidate | Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this issue. | Assigned (20071026) | None (candidate not yet proposed) | View | |
6692 | CVE-2002-2310 | Candidate | ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords. | Assigned (20071026) | None (candidate not yet proposed) | View | |
6691 | CVE-2002-2309 | Candidate | php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments. | Assigned (20071026) | None (candidate not yet proposed) | View |
Page 19605 of 20943, showing 5 records out of 104715 total, starting on record 98021, ending on 98025