CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6510 | CVE-2002-2128 | Candidate | editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6509 | CVE-2002-2127 | Candidate | Integrity Protection Driver (IPD) 1.2 and earlier blocks access to DevicePhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6508 | CVE-2002-2126 | Candidate | restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6507 | CVE-2002-2125 | Candidate | Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user"s local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6506 | CVE-2002-2124 | Candidate | The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing. | Assigned (20051028) | None (candidate not yet proposed) | View |
Page 19642 of 20943, showing 5 records out of 104715 total, starting on record 98206, ending on 98210