CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5670  CVE-2002-1286  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.  Modified (20071014)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5669  CVE-2002-1285  Candidate  runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox  CHANGE> [Cox changed vote from REVIEWING to MODIFY] | Cox> LPRng does not contain anything called runlpr, and in fact if you | look at the packages SuSE say that they ship as part of the erratum they | don"t even provide updated LPRng packages. However they do ship lprfilter | packages and looking inside them I find that they are what contain this | runlpr program: | | http://at.rpmfind.net/opsys/linux/RPM/suse.com/i386/update/8.0/ap1/lpdfilter-0.42-155.i386.html | | This states that lpdfilter is a collection of scripts written by SuSE, and | the changelog even highlights this is where the security fix was made. | Therefore I believe that the CVE reference and all the descriptions of | this vulnerability, which are based on a bad advisory description from | SuSE, are also wrong, it should be: | | "runlpr from the SuSE lpdfilter package allows the local lp user to gain | root privileges via certain command line arguments."  View
5668  CVE-2002-1284  Entry  The wizard in KGPG 0.6 through 0.8.2 does not properly provide the passphrase to gpg when creating new keys, which causes secret keys to be created with an empty passphrase and allows local attackers to steal the keys if they can be read.        View
5667  CVE-2002-1283  Candidate  Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.  Modified (20081001)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall | REVIEWING(1) Christey  Christey> Consider overlap with CVE-2002-1002 ? | See XF:novell-imanager-username-bo(9444) for more info  View
5666  CVE-2002-1282  Candidate  Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.  Modified (20071129)  ACCEPT(4) Armstrong, Cole, Cox, Green | NOOP(1) Christey  Christey> CALDERA:CSSA-2003-012.0 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-012.0.txt  View

Page 19810 of 20943, showing 5 records out of 104715 total, starting on record 99046, ending on 99050

Actions