CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2775  CVE-2000-1208  Candidate  Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Frech, Green | NOOP(2) Foat, Wall    View
5336  CVE-2002-0948  Candidate  Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.  Proposed (20020830)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
5337  CVE-2002-0949  Candidate  Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router"s password and other sensitive information in cleartext.  Proposed (20020830)  ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall    View
5338  CVE-2002-0950  Candidate  Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.  Proposed (20020830)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall  Green> Publisher has released update and a new version. | Unfortunately the homepage is in Japanese, making a | determination of whether or not the presenting problem has been | addressed rather speculative.  View
5339  CVE-2002-0951  Candidate  SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a ""--" sequence in the username and password.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(5) Cole, Cox, Foat, Green, Wall    View

Page 20896 of 20943, showing 5 records out of 104715 total, starting on record 104476, ending on 104480

Actions