CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5370  CVE-2002-0982  Candidate  Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.  Proposed (20020830)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:mssql-replication-sql-injection(9660)  View
5369  CVE-2002-0981  Entry  Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.        View
5368  CVE-2002-0980  Candidate  The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.  Modified (20050609)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> ADDREF MS:MS03-014 | URL:http://www.microsoft.com/technet/security/bulletin/ms03-014.asp | (it explicitly mentions this CAN). | | Note: MS03-014 places the blame on Outlook, not IE. | Frech> XF:ie-webfolder-script-injection(9881) | Christey> MS:MS03-014 | URL:http://www.microsoft.com/technet/security/bulletin/ms03-014.asp | | The following Bugtraq post appears to involve a different | attack vector than is currently described: | | BUGTRAQ:20030225 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part II | URL:http://www.securityfocus.com/archive/1/313174 | | *** FROM THE CVE PERSPECTIVE, THERE IS INSUFFICIENT PUBLIC | *** INFORMATION TO BE CERTAIN WHETHER THE ABOVE POST IS TRULY | *** ADDRESSED BY MS:MS03-014 OR NOT. THEREFORE IT IS NOT | *** CERTAIN WHETHER THE ABOVE REFERENCE SHOULD BE ADDED TO | *** THIS ENTRY OR NOT. | | The exploit from this Bugtraq post is being used in the | "W32/Mimail@MM" mail worm of July/August 2003. | | Also see: http://www.microsoft.com/security/incident/mimail.asp | | Also see: http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.a@mm.html  View
5367  CVE-2002-0979  Candidate  The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code.  Modified (20050610)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:ie-javalogging-code-execution(9886)  View
5366  CVE-2002-0978  Candidate  Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.  Proposed (20020830)  ACCEPT(2) Cole, LeBlanc | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat | REVIEWING(1) Wall  Christey> XF:ms-ftm-file-upload(9907) | URL:http://www.iss.net/security_center/static/9907.php | BID:5512 | URL:http://www.securityfocus.com/bid/5512 | | Discloser claimed bug was fixed, but I can"t find independent | acknowledgement from Microsoft. Inquiry sent to Microsoft on | November 18, 2002. They acknowledged, via email, that the | issue was fixed. | Frech> XF:ms-ftm-file-upload(9907)  View

Page 19870 of 20943, showing 5 records out of 104715 total, starting on record 99346, ending on 99350

Actions