CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5680 | CVE-2002-1296 | Entry | Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module. | View | |||
5679 | CVE-2002-1295 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability." | Modified (20050610) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
5678 | CVE-2002-1294 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods. | Modified (20050601) | ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall | View | |
5677 | CVE-2002-1293 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method. | Modified (20050610) | ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall | CHANGE> [Baker changed vote from MODIFY to ACCEPT] | View |
5676 | CVE-2002-1292 | Candidate | The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running. | Modified (20050510) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> Why is MS02-069 included here? This CAN is not mentioned in | the bulletin. | View |
Page 19808 of 20943, showing 5 records out of 104715 total, starting on record 99036, ending on 99040