CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4093  CVE-2001-1289  Candidate  Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:quake3-arena-connectre-bo(6930)  View
4606  CVE-2002-0214  Candidate  Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the WEP key from the registry key.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4607  CVE-2002-0215  Candidate  Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4864  CVE-2002-0472  Candidate  MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall    View
4866  CVE-2002-0474  Candidate  Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View

Page 20827 of 20943, showing 5 records out of 104715 total, starting on record 104131, ending on 104135

Actions