CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6873  CVE-2003-0044  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.  Modified (20071121)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | REVIEWING(1) Jones  Jones> [JHJ] XSS really "execute arbitrary web script"? | CHANGE> [Cox changed vote from NOOP to MODIFY] | Cox> "Agree with Jones, wording on effect of a XSS could be better" | Christey> I"ve been trying to devise reasonable-but-short wordings for | XSS issues and the terminology just isn"t quite there yet. This | description is clearly a failed wording, however :-)  View
6876  CVE-2003-0047  Candidate  SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.  Modified (20071121)  ACCEPT(2) Baker, Stracener | NOOP(4) Cole, Cox, Green, Wall  Green> MULTIPLE VENDORS INVOLVED | Stracener> I"m going to go with this because at least two of the affected vendors acknowledged a fix in the original advisory.  View
4115  CVE-2001-1311  Candidate  Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Modified (20071129)  ACCEPT(5) Cole, Foat, Frech, Green, Wall | NOOP(1) Cox | REVIEWING(1) Christey  Christey> Need to decide if regression errors should get their own CVE"s | or not. A regression error was introduced as explained in: | | VULNWATCH:20030313 R7-0012: Lotus Notes/Domino R6-beta PROTOS LDAP Denial of Service Regression | URL:http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0127.html | | This affects Domino R5.0.7 and earlier, and R6 pre-release/beta  View
5665  CVE-2002-1281  Candidate  Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain URL.  Modified (20071129)  ACCEPT(4) Armstrong, Cole, Cox, Green | NOOP(1) Christey  Christey> CALDERA:CSSA-2003-012.0 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-012.0.txt  View
5666  CVE-2002-1282  Candidate  Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.  Modified (20071129)  ACCEPT(4) Armstrong, Cole, Cox, Green | NOOP(1) Christey  Christey> CALDERA:CSSA-2003-012.0 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-012.0.txt  View

Page 20488 of 20943, showing 5 records out of 104715 total, starting on record 102436, ending on 102440

Actions