CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5365 | CVE-2002-0977 | Candidate | Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value. | Proposed (20020830) | ACCEPT(1) LeBlanc | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall | Christey> XF:ms-ftm-persist-bo(9906) | URL:http://www.iss.net/security_center/static/9906.php | BID:5508 | URL:http://www.securityfocus.com/bid/5508 | | Discloser claimed bug was fixed, but I can"t find independent | acknowledgement from Microsoft. Inquiry sent to Microsoft on | November 18, 2002. They acknowledged, via email, that the | issue was fixed. | Frech> XF:ms-ftm-persist-bo(9906) | View |
5364 | CVE-2002-0976 | Candidate | Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet. | Modified (20050610) | ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall | Frech> XF:ie-xml-read-files(9885) | View |
5363 | CVE-2002-0975 | Candidate | Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. | Modified (20071101) | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall | Christey> ADDREF MS:MS02-066 - "the patch sets the Kill Bit on a legacy | DirectX ActiveX control which has been retired but which has a | security vulnerability." | ADDREF MSKB:Q810202 - deals with "a security vulnerability | that exists in the DirectX Files Viewer control (Xweb.ocx)" | | Thanks to Andrew G. Tereschenko (the researcher) for this | additional information. | Frech> XF:ms-directx-files-viewer-bo(9877) | Christey> fix typo: "execute arbitrary [CODE]" | View |
5362 | CVE-2002-0974 | Entry | Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm. | View | |||
5361 | CVE-2002-0973 | Candidate | Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl. | Modified (20050529) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> BID:5493 | URL:http://online.securityfocus.com/bid/5493 | Frech> XF:freebsd-negative-system-call-bo(9903) | View |
Page 19871 of 20943, showing 5 records out of 104715 total, starting on record 99351, ending on 99355