CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6010  CVE-2002-1626  Candidate  Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL.  Assigned (20050326)  None (candidate not yet proposed)    View
6009  CVE-2002-1625  Candidate  Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CPU consumption) via the (1) loadMovie or (2) loadSound commands, which continue to execute until the browser is closed.  Assigned (20050326)  None (candidate not yet proposed)    View
6008  CVE-2002-1624  Candidate  Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.  Assigned (20050326)  None (candidate not yet proposed)    View
6007  CVE-2002-1623  Candidate  The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.  Assigned (20050326)  None (candidate not yet proposed)    View
6006  CVE-2002-1622  Candidate  Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."  Assigned (20050326)  None (candidate not yet proposed)    View

Page 19742 of 20943, showing 5 records out of 104715 total, starting on record 98706, ending on 98710

Actions