CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6695  CVE-2002-2313  Candidate  Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedded .mhtml file with ActiveX controls that execute a second embedded program, which is processed by Internet Explorer.  Assigned (20071026)  None (candidate not yet proposed)    View
6694  CVE-2002-2312  Candidate  Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.  Assigned (20071026)  None (candidate not yet proposed)    View
6693  CVE-2002-2311  Candidate  Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this issue.  Assigned (20071026)  None (candidate not yet proposed)    View
6692  CVE-2002-2310  Candidate  ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.  Assigned (20071026)  None (candidate not yet proposed)    View
6691  CVE-2002-2309  Candidate  php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.  Assigned (20071026)  None (candidate not yet proposed)    View

Page 19605 of 20943, showing 5 records out of 104715 total, starting on record 98021, ending on 98025

Actions