CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5096  CVE-2002-0706  Candidate  UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5098  CVE-2002-0708  Candidate  Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5099  CVE-2002-0709  Candidate  SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5359  CVE-2002-0971  Candidate  Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging System to bypass the VNC GUI and access the "Add new clients" dialogue box.  Modified (20050610)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:vnc-win32-messaging-privileges(9979)  View
5364  CVE-2002-0976  Candidate  Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.  Modified (20050610)  ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall  Frech> XF:ie-xml-read-files(9885)  View

Page 20433 of 20943, showing 5 records out of 104715 total, starting on record 102161, ending on 102165

Actions