CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4977  CVE-2002-0586  Candidate  Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via the Error or Notice parameters.  Proposed (20020611)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4979  CVE-2002-0588  Candidate  PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.  Proposed (20020611)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4980  CVE-2002-0589  Candidate  PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.  Proposed (20020611)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4725  CVE-2002-0333  Candidate  Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.  Proposed (20020502)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4726  CVE-2002-0334  Candidate  xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file.  Proposed (20020502)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View

Page 20017 of 20943, showing 5 records out of 104715 total, starting on record 100081, ending on 100085

Actions