CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5680  CVE-2002-1296  Entry  Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.        View
5679  CVE-2002-1295  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."  Modified (20050610)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5678  CVE-2002-1294  Candidate  The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.  Modified (20050601)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5677  CVE-2002-1293  Candidate  The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.  Modified (20050610)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall  CHANGE> [Baker changed vote from MODIFY to ACCEPT]  View
5676  CVE-2002-1292  Candidate  The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.  Modified (20050510)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> Why is MS02-069 included here? This CAN is not mentioned in | the bulletin.  View

Page 19808 of 20943, showing 5 records out of 104715 total, starting on record 99036, ending on 99040

Actions