CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4983 | CVE-2002-0592 | Candidate | AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user. | Modified (20050528) | MODIFY(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall | Frech> XF:aim-hijack-connection(8931) | View |
4480 | CVE-2002-0086 | Candidate | Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable. | Modified (20050528) | ACCEPT(3) Cole, Foat, Green | MODIFY(1) Balinsky | NOOP(3) Christey, Wall, Ziese | Christey> Consider adding BID:4317 | Christey> Consider adding BID:4319 | CHANGE> [Balinsky changed vote from ACCEPT to MODIFY] | Balinsky> Should say 5.0.4 through 5.0.9 (not including version 5.0.9a, which includes the fix) | Balinsky> Additional Modification: Should say "Linux and Solaris" | CHANGE> [Foat changed vote from NOOP to ACCEPT] | Christey> CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=92579CFD6F92B39A85256B7D006AC89B | CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=D52DF997ABFFFC8385256B7D0062AD5C | VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4126 - Lotus Domino bindsock Notes_ExecDirectory buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0046.html | VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4124 - Lotus Domino bindsock PATH buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0044.html | View |
4481 | CVE-2002-0087 | Candidate | bindsock in Lotus Domino 5.07 on Solaris allows local users to create arbitrary files via a symlink attack on temporary files. | Modified (20050528) | ACCEPT(4) Balinsky, Cole, Foat, Green | NOOP(3) Christey, Wall, Ziese | Christey> Consider adding BID:4318 | CHANGE> [Foat changed vote from NOOP to ACCEPT] | Christey> CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=93B3ED336951525385256B7D006A3CE3 | VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4125 - Lotus Domino bindsock arbitrary file creation vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0045.html | View |
3728 | CVE-2001-0922 | Candidate | ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in. | Modified (20050528) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:netdynamics-session-hijacking(7620) | View |
4530 | CVE-2002-0136 | Candidate | Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript. | Modified (20050528) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(2) Cole, Foat | REVIEWING(1) Wall | Frech> XF:ie-html-form-dos(7938) | View |
Page 20425 of 20943, showing 5 records out of 104715 total, starting on record 102121, ending on 102125