CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6230 | CVE-2002-1848 | Candidate | TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6229 | CVE-2002-1847 | Candidate | Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6228 | CVE-2002-1846 | Candidate | Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6227 | CVE-2002-1845 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6226 | CVE-2002-1844 | Candidate | Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges. | Assigned (20050629) | None (candidate not yet proposed) | View |
Page 19698 of 20943, showing 5 records out of 104715 total, starting on record 98486, ending on 98490