CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10408  CVE-2004-1982  Candidate  Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board"s .txt file via carriage return characters in the subject field.  Assigned (20050504)  REVIEWING(1) Christey  Christey> likely dupe with CVE-2004-2140  View
1434  CVE-1999-1454  Candidate  Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.  Proposed (20010912)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Foat, Wall  Christey> Looks like there might have been a re-discovery, though the | exploit is slightly different, and there is insufficient | detail to be certain that this isn"t for a different | Matrix screen saver: | BUGTRAQ:20010801 matrix screensvr(16 Bit CineMac Screen Saver Engine) - [input validation error?] | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99669949717618&w=2 | BID:3130 | URL:http://www.securityfocus.com/bid/3130 | Frech> XF:matrix-win95-password-bypass(8280)  View
2322  CVE-2000-0746  Candidate  Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.  Proposed (20000921)  ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Christey> Make sure both BID"s are appropriate | XF:iis-cross-site-scripting | http://xforce.iss.net/static/5156.php | Frech> XF: iis-cross-site-scripting(5156) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> A re-release of MS:MS00-060 indicates that a new variant of | this problem was discovered, but the advisory does not | provide sufficient details to distinguish it from this | candidate. A new candidate is being created, but the | description can"t be written without mentioning this CAN.  View
4791  CVE-2002-0399  Candidate  Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.  Modified (20100521)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2002:066 | Cox> Addref: RHSA-2002:138  View
5752  CVE-2002-1368  Candidate  Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.  Modified (20071220)  ACCEPT(3) Cole, Cox, Green | NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:001  View

Page 20642 of 20943, showing 5 records out of 104715 total, starting on record 103206, ending on 103210

Actions