CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6455 | CVE-2002-2073 | Candidate | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6454 | CVE-2002-2072 | Candidate | java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6453 | CVE-2002-2071 | Candidate | Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6) ttdbserverd, and possibly other services via a TCP SYN scan, as demonstrated using nmap. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6452 | CVE-2002-2070 | Candidate | SecureClean 3 build 2.0 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6451 | CVE-2002-2069 | Candidate | PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 19653 of 20943, showing 5 records out of 104715 total, starting on record 98261, ending on 98265