CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6510  CVE-2002-2128  Candidate  editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter.  Assigned (20051116)  None (candidate not yet proposed)    View
6509  CVE-2002-2127  Candidate  Integrity Protection Driver (IPD) 1.2 and earlier blocks access to DevicePhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.  Assigned (20051116)  None (candidate not yet proposed)    View
6508  CVE-2002-2126  Candidate  restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.  Assigned (20051116)  None (candidate not yet proposed)    View
6507  CVE-2002-2125  Candidate  Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user"s local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.  Assigned (20051116)  None (candidate not yet proposed)    View
6506  CVE-2002-2124  Candidate  The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing.  Assigned (20051028)  None (candidate not yet proposed)    View

Page 19642 of 20943, showing 5 records out of 104715 total, starting on record 98206, ending on 98210

Actions