CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6555 | CVE-2002-2173 | Candidate | Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6554 | CVE-2002-2172 | Candidate | Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6553 | CVE-2002-2171 | Candidate | Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6552 | CVE-2002-2170 | Candidate | Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6551 | CVE-2002-2169 | Candidate | Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user"s buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL. | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 19633 of 20943, showing 5 records out of 104715 total, starting on record 98161, ending on 98165