CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5227 | CVE-2002-0837 | Candidate | wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") to the wordtrans.php script. | Proposed (20030317) | ACCEPT(4) Armstrong, Cole, Cox, Green | Cox> I believe this to mean "multiple exploit vectors" for the single | vulnerability. The patch to correct this issue was a single line that | would remove any non-alphabetic characters from the "dict" parameter. | View |
5739 | CVE-2002-1355 | Candidate | Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages. | Proposed (20030317) | ACCEPT(2) Cole, Green | MODIFY(1) Cox | Cox> Addref: REDHAT:RHSA-2002:291 | View |
5228 | CVE-2002-0838 | Candidate | Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Frech, Wall | MODIFY(1) Cox | NOOP(1) Christey | Cox> Addref: RHSA-2002:211 | Christey> GENTOO:GLSA-200408-10 | URL:http://www.gentoo.org/security/en/glsa/glsa-200408-10.xml | View |
5740 | CVE-2002-1356 | Candidate | Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages. | Proposed (20030317) | ACCEPT(2) Cole, Green | MODIFY(1) Cox | Cox> Addref: REDHAT:RHSA-2002:291 | View |
5487 | CVE-2002-1100 | Candidate | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | View |
Page 26 of 20943, showing 5 records out of 104715 total, starting on record 126, ending on 130