CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10408 | CVE-2004-1982 | Candidate | Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board"s .txt file via carriage return characters in the subject field. | Assigned (20050504) | REVIEWING(1) Christey | Christey> likely dupe with CVE-2004-2140 | View |
1434 | CVE-1999-1454 | Candidate | Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key. | Proposed (20010912) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Foat, Wall | Christey> Looks like there might have been a re-discovery, though the | exploit is slightly different, and there is insufficient | detail to be certain that this isn"t for a different | Matrix screen saver: | BUGTRAQ:20010801 matrix screensvr(16 Bit CineMac Screen Saver Engine) - [input validation error?] | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99669949717618&w=2 | BID:3130 | URL:http://www.securityfocus.com/bid/3130 | Frech> XF:matrix-win95-password-bypass(8280) | View |
2322 | CVE-2000-0746 | Candidate | Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities. | Proposed (20000921) | ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> Make sure both BID"s are appropriate | XF:iis-cross-site-scripting | http://xforce.iss.net/static/5156.php | Frech> XF: iis-cross-site-scripting(5156) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> A re-release of MS:MS00-060 indicates that a new variant of | this problem was discovered, but the advisory does not | provide sufficient details to distinguish it from this | candidate. A new candidate is being created, but the | description can"t be written without mentioning this CAN. | View |
4791 | CVE-2002-0399 | Candidate | Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267. | Modified (20100521) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2002:066 | Cox> Addref: RHSA-2002:138 | View |
5752 | CVE-2002-1368 | Candidate | Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding. | Modified (20071220) | ACCEPT(3) Cole, Cox, Green | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:001 | View |
Page 20642 of 20943, showing 5 records out of 104715 total, starting on record 103206, ending on 103210