CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5071  CVE-2002-0681  Candidate  Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.  Modified (20040725)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> XF:goahead-error-msg-xss(9518) | URL:http://www.iss.net/security_center/static/9518.php | BID:5198 | URL:http://www.securityfocus.com/bid/5198 | Christey> XF:goahead-encoded-directory-traversal(9519) | URL:http://www.iss.net/security_center/static/9519.php | BID:5197 | URL:http://www.securityfocus.com/bid/5197 | Frech> XF:goahead-error-msg-xss(9518)  View
5115  CVE-2002-0725  Candidate  NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.  Modified (20040725)  ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Cox | REVIEWING(1) Wall  Christey> XF:win-ntfs-bypass-auditing(9869) | URL:http://www.iss.net/security_center/static/9869.php | BID:5484 | URL:http://www.securityfocus.com/bid/5484 | Frech> XF:win-ntfs-bypass-auditing(9869)  View
5507  CVE-2002-1120  Candidate  Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.  Modified (20040804)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
4877  CVE-2002-0485  Candidate  Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.  Modified (20040811)  ACCEPT(1) Prosser | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nav-case-bypass-protection(9860) | Prosser> This issues was a continuation of an earlier reported issue | with non-RFC compliant MIME headers. The discover was testing a | non-updated version of NAV 2002 which was vulnerable to this and other | non-RFC compliant configurations. Updated and current releases are not | vulnerable to this problem | | http://securityresponse.symantec.com/avcenter/security/Content/2002.04.03.html | is the posted response to this issue.  View
33  CVE-1999-0033  Candidate  Command execution in Sun systems via buffer overflow in the at program.  Modified (20040811)  ACCEPT(8) Baker, Cole, Collins, Dik, Hill, Northcutt, Shostack, Wall | NOOP(1) Christey | RECAST(1) Frech  Frech> This vulnerability also manifests itself for the following | platforms: AIX, HPUX, IRIX, Solaris, SCO, NCR MP-RAS. In this light, | please add the following: | Reference: XF:at-bo | Dik> Sun bug 1265200, 4063161 | Christey> ADDREF SGI:19971102-01-PX | ftp://patches.sgi.com/support/free/security/advisories/19971102-01-PX | SCO:SB.97:01 | ftp://ftp.sco.com/SSE/security_bulletins/SB.97:01a | Christey> CIAC:F-15 | http://ciac.llnl.gov/ciac/bulletins/f-15.shtml | HP:HPSBUX9502-023 | Christey> Add period to the end of the description.  View

Page 20401 of 20943, showing 5 records out of 104715 total, starting on record 102001, ending on 102005

Actions