CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6555  CVE-2002-2173  Candidate  Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message.  Assigned (20051116)  None (candidate not yet proposed)    View
6554  CVE-2002-2172  Candidate  Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information.  Assigned (20051116)  None (candidate not yet proposed)    View
6553  CVE-2002-2171  Candidate  Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL.  Assigned (20051116)  None (candidate not yet proposed)    View
6552  CVE-2002-2170  Candidate  Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.  Assigned (20051116)  None (candidate not yet proposed)    View
6551  CVE-2002-2169  Candidate  Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user"s buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.  Assigned (20051116)  None (candidate not yet proposed)    View

Page 19633 of 20943, showing 5 records out of 104715 total, starting on record 98161, ending on 98165

Actions