CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2300 | CVE-2000-0724 | Candidate | The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:go-gnome-preinstaller-symlink(5161) | Frech> XF:go-gnome-preinstaller-symlink(5161) | View |
2299 | CVE-2000-0723 | Candidate | Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:gnome-installer-overwrite-configuration(5129) | Frech> XF:gnome-installer-overwrite-configuration(5129) | View |
2948 | CVE-2001-0127 | Candidate | Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag. | Modified (20050509) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:flash-module-bo | Frech> XF:flash-module-bo(5952) | View |
4622 | CVE-2002-0230 | Candidate | Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message. | Proposed (20020502) | ACCEPT(2) Cole, Green | NOOP(2) Foat, Wall | RECAST(1) Christey | Christey> XF:faqomatic-cgi-css(8066) | URL:http://www.iss.net/security_center/static/8066.php | BID:4023 | URL:http://www.securityfocus.com/bid/4023 | | A similar issue was discovered a few months afterward in the | "file" parameter, but it was already fixed by the vendor along | with the cmd parameter. Thus CD:SF-LOC suggests combining | these into a single item. | CONFIRM:http://sourceforge.net/mailarchive/forum.php?thread_id=477665&forum_id=6367 | BID:4565 | URL:http://www.securityfocus.com/bid/4565 | View |
5910 | CVE-2002-1526 | Candidate | Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field. | Modified (20071016) | ACCEPT(2) Armstrong, Baker | NOOP(4) Christey, Cole, Cox, Wall | Christey> XF:emu-webmail-address-xss(10205) | URL:http://www.iss.net/security_center/static/10205.php | View |
Page 275 of 20943, showing 5 records out of 104715 total, starting on record 1371, ending on 1375