CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5375  CVE-2002-0987  Entry  X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.        View
5374  CVE-2002-0986  Entry  The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."        View
5373  CVE-2002-0985  Entry  Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.        View
5372  CVE-2002-0984  Entry  The IRC script included in Light 2.7.x before 2.7.30p5, and 2.8.x before 2.8pre10, running EPIC allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC4 code.        View
5371  CVE-2002-0983  Candidate  IRC client irssi in irssi-text before 0.8.4 allows remote attackers to cause a denial of service (crash) via an IRC channel that has a long topic followed by a certain string, possibly triggering a buffer overflow.  Modified (20050528)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> BUGTRAQ:20020619 DoS on irssi 0.8.4 | URL:http://online.securityfocus.com/archive/1/277686 | XF:irssi-long-topic-dos(9395) | URL:http://www.iss.net/security_center/static/9395.php | Frech> XF:irssi-long-topic-dos(9395)  View

Page 19869 of 20943, showing 5 records out of 104715 total, starting on record 99341, ending on 99345

Actions