CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6010 | CVE-2002-1626 | Candidate | Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL. | Assigned (20050326) | None (candidate not yet proposed) | View | |
6009 | CVE-2002-1625 | Candidate | Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CPU consumption) via the (1) loadMovie or (2) loadSound commands, which continue to execute until the browser is closed. | Assigned (20050326) | None (candidate not yet proposed) | View | |
6008 | CVE-2002-1624 | Candidate | Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters. | Assigned (20050326) | None (candidate not yet proposed) | View | |
6007 | CVE-2002-1623 | Candidate | The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote. | Assigned (20050326) | None (candidate not yet proposed) | View | |
6006 | CVE-2002-1622 | Candidate | Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type." | Assigned (20050326) | None (candidate not yet proposed) | View |
Page 19742 of 20943, showing 5 records out of 104715 total, starting on record 98706, ending on 98710