CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5076  CVE-2002-0686  Candidate  Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.  Modified (20050328)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> XF:iplanet-search-bo(9506) | URL:http://www.iss.net/security_center/static/9506.php | BID:4851 | URL:http://www.securityfocus.com/bid/4851 | Frech> XF:iplanet-search-bo(9506)  View
2953  CVE-2001-0132  Candidate  Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.  Proposed (20010214)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:interscan-viruswall-symlink | URL:http://xforce.iss.net/static/5947.php | Frech> XF:interscan-viruswall-symlink(5947)  View
5264  CVE-2002-0874  Candidate  Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.  Proposed (20020830)  ACCEPT(4) Armstrong, Baker, Cole, Cox | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> XF:interchange-inet-read-files(9833) | URL:http://www.iss.net/security_center/static/9833.php | BID:5453 | URL:http://www.securityfocus.com/bid/5453 | | Modify desc to say "unknown vulnerability" to emphasize that | the actual cause of the problem is unknown. | Frech> XF:interchange-inet-read-files(9833)  View
4763  CVE-2002-0371  Candidate  Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.  Modified (20061101)  ACCEPT(4) Baker, Cole, Foat, Wall | NOOP(2) Christey, Cox  Christey> XF:ie-gopher-bo(9247) | URL:http://www.iss.net/security_center/static/9247.php | CERT-VN:VU#440275 | URL:http://www.kb.cert.org/vuls/id/440275 | BID:4930 | URL:http://www.securityfocus.com/bid/4930 | Christey> Investigate: should this include IE 5.01? | Christey> Note: CVE-2002-0646 was accidentally assigned to this issue. | That candidate will be rejected in favor of this one. | | ADDREF MS:MS02-047 | | ADDREF BUGTRAQ:20020729 Re: Eat gopher! | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102796732424646&w=2  View
5071  CVE-2002-0681  Candidate  Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.  Modified (20040725)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> XF:goahead-error-msg-xss(9518) | URL:http://www.iss.net/security_center/static/9518.php | BID:5198 | URL:http://www.securityfocus.com/bid/5198 | Christey> XF:goahead-encoded-directory-traversal(9519) | URL:http://www.iss.net/security_center/static/9519.php | BID:5197 | URL:http://www.securityfocus.com/bid/5197 | Frech> XF:goahead-error-msg-xss(9518)  View

Page 274 of 20943, showing 5 records out of 104715 total, starting on record 1366, ending on 1370

Actions