CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
650 | CVE-1999-0669 | Candidate | The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. | Interim (19991229) | ACCEPT(5) Baker, Cole, Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REVIEWING(1) Christey | Frech> XF:ms-scriptlet-eyedog-unsafe | Stracener> Add Ref: MSKB Q240308 | Christey> Should CVE-1999-0669 and 668 be merged? If not, then this is | a reason for not merging CVE-1999-0988 and CVE-1999-0828. | View |
3068 | CVE-2001-0247 | Candidate | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3. | Modified (20010910-01) | ACCEPT(5) Baker, Cole, Oliver, Renaud, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:ftp-glob-expansion(6332) | Christey> ADDREF SGI:20010802-01-P | Christey> COMPAQ:SSRT-547 | URL:http://archives.neohapsis.com/archives/tru64/2002-q3/0017.html | View |
3067 | CVE-2001-0246 | Candidate | Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability. | Proposed (20010524) | ACCEPT(5) Baker, Cole, Magdych, Wall, Williams | MODIFY(1) Frech | NOOP(2) Renaud, Ziese | REVIEWING(1) Christey | Christey> See comments for CVE-2001-0332; may need to be merged because | of CD:SF-LOC. | Frech> XF:ie-frame-verification-variant(6748) | View |
1844 | CVE-2000-0266 | Candidate | Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. | Proposed (20000426) | ACCEPT(5) Baker, Cole, LeBlanc, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:ie-java-crossframe-security | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0028 may | also be a variant. | LeBlanc> MS00-039 | View |
2866 | CVE-2001-0045 | Candidate | The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities. | Modified (20061101) | ACCEPT(5) Baker, Cole, Frech, Wall, Ziese | View |
Page 19873 of 20943, showing 5 records out of 104715 total, starting on record 99361, ending on 99365