CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9563  CVE-2004-1135  Candidate  Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.  Assigned (20041205)  NOOP(1) Christey  Christey> NOTE: CVE-2004-1135 is for the WS_FTP overflows. It was mistakenly | linked to an issue in w3who (CVE-2004-1133 or CVE-2004-1134)  View
5252  CVE-2002-0862  Candidate  The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> Note: CVE-2002-0828 is an earlier discovery of this candidate. | That candidate will be REJECTED in favor of this one, | which comes from a more authoritative source and is | more accurate.  View
3906  CVE-2001-1102  Candidate  Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(6) Armstrong, Christey, Cole, Foat, Wall, Ziese  Christey> NOTE: CVE-2001-1171 was discovered to be a duplicate of this | issue. Use this candidate (CVE-2001-1102) instead of the | other one.  View
1002  CVE-1999-1022  Candidate  serial_ports administrative program in IRIX 4.x and 5.x trusts the user"s PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.  Proposed (20010912)  ACCEPT(2) Cole, Frech | NOOP(2) Christey, Foat  Christey> Note: CVE-1999-1310 is a duplicate of this candidate. | CVE-1999-1310 will be REJECTed; this is the proper CAN to use. | | CIAC:F-01 | URL:http://ciac.llnl.gov/ciac/bulletins/f-01.shtml | SGI:19941001-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/19941001-01-P | MISC:http://www.netsys.com/firewalls/firewalls-9410/0019.html  View
4581  CVE-2002-0189  Candidate  Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.  Modified (20061101)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Christey  Christey> NOTE: As of 5/20/2002, there is a lack of clarity regarding | the details of this vulnerability and other vulnerabilities | being reported by GreyMagic and Thor Larholm. Additional | details will be added to this candidate if/when they become | available. This candidate is solely for the issue that is | being addressed by Microsoft in MS:MS02-023. Its relationship | with other reported issues is currently unproven. | | This candidate is subject to CD:VAGUE. | Christey> XF:ie-dialog-window-css(8868) | URL:http://www.iss.net/security_center/static/8868.php | Frech> XF:ie-dialog-window-css(8868) | Baker> I agree some of the information appears vague, but seems to be legitimate.  View

Page 295 of 20943, showing 5 records out of 104715 total, starting on record 1471, ending on 1475

Actions