CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6865 | CVE-2003-0036 | Candidate | ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d". | Modified (20080326) | ACCEPT(2) Armstrong, Green | NOOP(3) Cole, Cox, Jones | Green> APPEARS IN MANDRAKE SECURITY ADVISORY MDKSA-2003:010 | THIS EXPLOIT DIFFERS FROM THE SYMLINK IN A SAMSUNG PRINTER REFERENCED IN CVE-2001-1177. | View |
5719 | CVE-2002-1335 | Candidate | Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies. | Modified (20071129) | ACCEPT(2) Armstrong, Green | NOOP(2) Cole, Cox | Cox> The wording of the impact of this issue could be better, this is | just a cross-site scripting vulnerability | Addref: RHSA-2003:045 | Green> ACKNOWLEDGED IN THE SOURCEFORGE NOTES | View |
5781 | CVE-2002-1397 | Candidate | Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow. | Modified (20071113) | ACCEPT(2) Armstrong, Green | MODIFY(1) Cox | NOOP(1) Cole | Cox> Addref: RHSA-2003:010 | Addref: RHSA-2003:001 | Addref: RHSA-2002:301 | View |
5782 | CVE-2002-1398 | Candidate | Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input." | Modified (20071113) | ACCEPT(2) Armstrong, Green | MODIFY(1) Cox | NOOP(1) Cole | Cox> Addref: RHSA-2003:010 | Addref: RHSA-2003:001 | Addref: RHSA-2002:301 | View |
5784 | CVE-2002-1400 | Candidate | Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. | Modified (20071113) | ACCEPT(2) Armstrong, Green | MODIFY(1) Cox | NOOP(1) Cole | Cox> Addref: RHSA-2003:010 | Addref: RHSA-2003:001 | Addref: RHSA-2002:301 | View |
Page 20179 of 20943, showing 5 records out of 104715 total, starting on record 100891, ending on 100895