CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4208 | CVE-2001-1405 | Candidate | Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Cox> Right CD? | Frech> XF:bugzilla-sanitycheck-dos(10481) | View |
5690 | CVE-2002-1306 | Candidate | Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL. | Proposed (20030317) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | Cox> Suggest adding "KDE" into description | Addref: RHSA-2002:221 | View |
4819 | CVE-2002-0427 | Candidate | Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges. | Proposed (20020611) | ACCEPT(4) Alderson, Baker, Cole, Frech | MODIFY(1) Cox | NOOP(2) Foat, Wall | Cox> The description should say "improved mod_frontpage" as there | are two Frontpage modules for Apache, the offical one and this one. | View |
5047 | CVE-2002-0657 | Candidate | Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat | Cox> The majority of the vendor references listed are incorrect, those vendors | did not ship 0.9.7. Each one should be checked for accuracy, those | not shipping 0.9.7 were not affected. | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | View |
5719 | CVE-2002-1335 | Candidate | Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies. | Modified (20071129) | ACCEPT(2) Armstrong, Green | NOOP(2) Cole, Cox | Cox> The wording of the impact of this issue could be better, this is | just a cross-site scripting vulnerability | Addref: RHSA-2003:045 | Green> ACKNOWLEDGED IN THE SOURCEFORGE NOTES | View |
Page 20693 of 20943, showing 5 records out of 104715 total, starting on record 103461, ending on 103465