CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5676  CVE-2002-1292  Candidate  The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.  Modified (20050510)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> Why is MS02-069 included here? This CAN is not mentioned in | the bulletin.  View
5252  CVE-2002-0862  Candidate  The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> Note: CVE-2002-0828 is an earlier discovery of this candidate. | That candidate will be REJECTED in favor of this one, | which comes from a more authoritative source and is | more accurate.  View
5253  CVE-2002-0863  Candidate  Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> ADDREF CERT-VN:VU#865833 | URL:http://www.kb.cert.org/vuls/id/865833  View
4082  CVE-2001-1278  Candidate  Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Foat | REJECT(3) Christey, Cox, Frech  Christey> Agreed; dupe of CVE-2001-1227  View
5638  CVE-2002-1254  Candidate  Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."  Modified (20071101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View

Page 19962 of 20943, showing 5 records out of 104715 total, starting on record 99806, ending on 99810

Actions