CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5955  CVE-2002-1571  Candidate  The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.  Assigned (20031126)  None (candidate not yet proposed)    View
5954  CVE-2002-1570  Candidate  Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array.  Assigned (20031030)  None (candidate not yet proposed)    View
5953  CVE-2002-1569  Candidate  gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file.  Assigned (20031022)  None (candidate not yet proposed)    View
5952  CVE-2002-1568  Candidate  OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.  Assigned (20031006)  None (candidate not yet proposed)    View
5951  CVE-2002-1567  Candidate  Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.  Assigned (20030918)  None (candidate not yet proposed)    View

Page 19753 of 20943, showing 5 records out of 104715 total, starting on record 98761, ending on 98765

Actions