CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5565  CVE-2002-1181  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5564  CVE-2002-1180  Entry  A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."        View
5563  CVE-2002-1179  Entry  Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.        View
5562  CVE-2002-1178  Entry  Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via .. (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.        View
5561  CVE-2002-1177  Candidate  Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.  Modified (20080304)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 19831 of 20943, showing 5 records out of 104715 total, starting on record 99151, ending on 99155

Actions