CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5719  CVE-2002-1335  Candidate  Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.  Modified (20071129)  ACCEPT(2) Armstrong, Green | NOOP(2) Cole, Cox  Cox> The wording of the impact of this issue could be better, this is | just a cross-site scripting vulnerability | Addref: RHSA-2003:045 | Green> ACKNOWLEDGED IN THE SOURCEFORGE NOTES  View
5047  CVE-2002-0657  Candidate  Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat  Cox> The majority of the vendor references listed are incorrect, those vendors | did not ship 0.9.7. Each one should be checked for accuracy, those | not shipping 0.9.7 were not affected. | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13  View
4819  CVE-2002-0427  Candidate  Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | MODIFY(1) Cox | NOOP(2) Foat, Wall  Cox> The description should say "improved mod_frontpage" as there | are two Frontpage modules for Apache, the offical one and this one.  View
5690  CVE-2002-1306  Candidate  Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox  Cox> Suggest adding "KDE" into description | Addref: RHSA-2002:221  View
4208  CVE-2001-1405  Candidate  Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.  Proposed (20020830)  ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat  Cox> Right CD? | Frech> XF:bugzilla-sanitycheck-dos(10481)  View

Page 251 of 20943, showing 5 records out of 104715 total, starting on record 1251, ending on 1255

Actions