CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3775  CVE-2001-0970  Candidate  Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.  Modified (20071006)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Green> HAS-INDEPENDENT-CONFIRMATION | Frech> XF:tdforum-cross-site-scripting(7009)  View
3777  CVE-2001-0972  Candidate  Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."  Modified (20071006)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:surfnet-asp-cookie-seq-predictable(7011)  View
5670  CVE-2002-1286  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.  Modified (20071014)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5672  CVE-2002-1288  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.  Modified (20071014)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5673  CVE-2002-1289  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters.  Modified (20071014)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View

Page 20470 of 20943, showing 5 records out of 104715 total, starting on record 102346, ending on 102350

Actions