CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5157  CVE-2002-0767  Candidate  simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5160  CVE-2002-0770  Candidate  Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."  Modified (20051128)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5161  CVE-2002-0771  Candidate  Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5162  CVE-2002-0772  Candidate  Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parameter.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
5163  CVE-2002-0773  Candidate  imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) owwwPath, and (3) oftpPath.  Proposed (20020726)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View

Page 20939 of 20943, showing 5 records out of 104715 total, starting on record 104691, ending on 104695

Actions