CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5830  CVE-2002-1446  Entry  The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.        View
5829  CVE-2002-1445  Candidate  Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5828  CVE-2002-1444  Candidate  The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5827  CVE-2002-1443  Entry  The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user"s input into the toolbar via an "onkeydown" event handler.        View
5826  CVE-2002-1442  Candidate  The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window"s location to the toolbar"s configuration URL, which bypasses the origin verification check.  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View

Page 19778 of 20943, showing 5 records out of 104715 total, starting on record 98886, ending on 98890

Actions