CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2300  CVE-2000-0724  Candidate  The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:go-gnome-preinstaller-symlink(5161) | Frech> XF:go-gnome-preinstaller-symlink(5161)  View
2299  CVE-2000-0723  Candidate  Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:gnome-installer-overwrite-configuration(5129) | Frech> XF:gnome-installer-overwrite-configuration(5129)  View
2948  CVE-2001-0127  Candidate  Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.  Modified (20050509)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:flash-module-bo | Frech> XF:flash-module-bo(5952)  View
4622  CVE-2002-0230  Candidate  Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.  Proposed (20020502)  ACCEPT(2) Cole, Green | NOOP(2) Foat, Wall | RECAST(1) Christey  Christey> XF:faqomatic-cgi-css(8066) | URL:http://www.iss.net/security_center/static/8066.php | BID:4023 | URL:http://www.securityfocus.com/bid/4023 | | A similar issue was discovered a few months afterward in the | "file" parameter, but it was already fixed by the vendor along | with the cmd parameter. Thus CD:SF-LOC suggests combining | these into a single item. | CONFIRM:http://sourceforge.net/mailarchive/forum.php?thread_id=477665&forum_id=6367 | BID:4565 | URL:http://www.securityfocus.com/bid/4565  View
5910  CVE-2002-1526  Candidate  Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.  Modified (20071016)  ACCEPT(2) Armstrong, Baker | NOOP(4) Christey, Cole, Cox, Wall  Christey> XF:emu-webmail-address-xss(10205) | URL:http://www.iss.net/security_center/static/10205.php  View

Page 275 of 20943, showing 5 records out of 104715 total, starting on record 1371, ending on 1375

Actions