CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6140  CVE-2002-1758  Candidate  PHProjekt 2.0 through 3.1 allows remote attackers to view or modify data via requests to certain scripts that do not verify if the user is logged in.  Assigned (20050621)  None (candidate not yet proposed)    View
6139  CVE-2002-1757  Candidate  PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms".  Assigned (20050621)  None (candidate not yet proposed)    View
6138  CVE-2002-1756  Candidate  ACDSee 4.0 allows remote attackers to cause a denial of service (crash) via an .ais file with a long file description field, which is not properly handled when the file properties of the file are viewed.  Assigned (20050621)  None (candidate not yet proposed)    View
6137  CVE-2002-1755  Candidate  tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.  Assigned (20050621)  None (candidate not yet proposed)    View
6136  CVE-2002-1754  Candidate  Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19716 of 20943, showing 5 records out of 104715 total, starting on record 98576, ending on 98580

Actions