CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4861 | CVE-2002-0469 | Candidate | Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA"s, which could allow local users to gain privileges. | Proposed (20020611) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | View | |
5120 | CVE-2002-0730 | Candidate | Cross-site scripting vulnerability in guestbook.pl for Philip Chinery"s Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage. | Proposed (20020726) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
5121 | CVE-2002-0731 | Candidate | Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl. | Proposed (20020726) | ACCEPT(1) Cole | NOOP(4) Armstrong, Cox, Foat, Wall | View | |
5122 | CVE-2002-0732 | Candidate | Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments. | Proposed (20020726) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall | View | |
5125 | CVE-2002-0735 | Candidate | Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages. | Proposed (20020726) | ACCEPT(2) Armstrong, Cole | NOOP(3) Cox, Foat, Wall | View |
Page 20856 of 20943, showing 5 records out of 104715 total, starting on record 104276, ending on 104280