CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5676 | CVE-2002-1292 | Candidate | The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running. | Modified (20050510) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> Why is MS02-069 included here? This CAN is not mentioned in | the bulletin. | View |
5252 | CVE-2002-0862 | Candidate | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> Note: CVE-2002-0828 is an earlier discovery of this candidate. | That candidate will be REJECTED in favor of this one, | which comes from a more authoritative source and is | more accurate. | View |
5253 | CVE-2002-0863 | Candidate | Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol." | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> ADDREF CERT-VN:VU#865833 | URL:http://www.kb.cert.org/vuls/id/865833 | View |
4082 | CVE-2001-1278 | Candidate | Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags. | Proposed (20020502) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Foat | REJECT(3) Christey, Cox, Frech | Christey> Agreed; dupe of CVE-2001-1227 | View |
5638 | CVE-2002-1254 | Candidate | Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods." | Modified (20071101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View |
Page 19962 of 20943, showing 5 records out of 104715 total, starting on record 99806, ending on 99810