CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5365  CVE-2002-0977  Candidate  Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value.  Proposed (20020830)  ACCEPT(1) LeBlanc | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> XF:ms-ftm-persist-bo(9906) | URL:http://www.iss.net/security_center/static/9906.php | BID:5508 | URL:http://www.securityfocus.com/bid/5508 | | Discloser claimed bug was fixed, but I can"t find independent | acknowledgement from Microsoft. Inquiry sent to Microsoft on | November 18, 2002. They acknowledged, via email, that the | issue was fixed. | Frech> XF:ms-ftm-persist-bo(9906)  View
5364  CVE-2002-0976  Candidate  Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.  Modified (20050610)  ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall  Frech> XF:ie-xml-read-files(9885)  View
5363  CVE-2002-0975  Candidate  Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.  Modified (20071101)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> ADDREF MS:MS02-066 - "the patch sets the Kill Bit on a legacy | DirectX ActiveX control which has been retired but which has a | security vulnerability." | ADDREF MSKB:Q810202 - deals with "a security vulnerability | that exists in the DirectX Files Viewer control (Xweb.ocx)" | | Thanks to Andrew G. Tereschenko (the researcher) for this | additional information. | Frech> XF:ms-directx-files-viewer-bo(9877) | Christey> fix typo: "execute arbitrary [CODE]"  View
5362  CVE-2002-0974  Entry  Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm.        View
5361  CVE-2002-0973  Candidate  Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.  Modified (20050529)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> BID:5493 | URL:http://online.securityfocus.com/bid/5493 | Frech> XF:freebsd-negative-system-call-bo(9903)  View

Page 19871 of 20943, showing 5 records out of 104715 total, starting on record 99351, ending on 99355

Actions