CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6340  CVE-2002-1958  Candidate  Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.  Assigned (20050629)  None (candidate not yet proposed)    View
6339  CVE-2002-1957  Candidate  Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages.  Assigned (20050629)  None (candidate not yet proposed)    View
6338  CVE-2002-1956  Candidate  ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files.  Assigned (20050629)  None (candidate not yet proposed)    View
6337  CVE-2002-1955  Candidate  Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack.  Assigned (20050629)  None (candidate not yet proposed)    View
6336  CVE-2002-1954  Candidate  Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 19676 of 20943, showing 5 records out of 104715 total, starting on record 98376, ending on 98380

Actions