CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4896  CVE-2002-0504  Candidate  Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4899  CVE-2002-0507  Candidate  An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(3) Armstrong, Cox, Foat | REVIEWING(1) Wall    View
4900  CVE-2002-0508  Candidate  wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.  Proposed (20020611)  ACCEPT(3) Baker, Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4901  CVE-2002-0509  Candidate  Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4902  CVE-2002-0510  Candidate  The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.  Proposed (20020611)  ACCEPT(3) Foat, Frech, Green | NOOP(3) Cole, Cox, Wall  CHANGE> [Cox changed vote from REVIEWING to NOOP] | Cox> So I asked some kernel guys about this - it"s not considered | an issue. There are several other ways to identify Linux on | the wire and people who care about this kind of thing rewrite | their packets in various ways via firewall technology to trick | the identifier programs.  View

Page 20832 of 20943, showing 5 records out of 104715 total, starting on record 104156, ending on 104160

Actions