CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5130 | CVE-2002-0740 | Candidate | Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument. | Proposed (20020726) | ACCEPT(1) Cox | NOOP(4) Armstrong, Cole, Foat, Wall | View | |
5129 | CVE-2002-0739 | Candidate | Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page. | Proposed (20020726) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
5128 | CVE-2002-0738 | Entry | MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3) using "&={script}" syntax. | View | |||
5127 | CVE-2002-0737 | Entry | Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character. | View | |||
5126 | CVE-2002-0736 | Entry | Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. | View |
Page 19918 of 20943, showing 5 records out of 104715 total, starting on record 99586, ending on 99590