CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5767 | CVE-2002-1383 | Candidate | Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun. | Modified (20071220) | ACCEPT(3) Cole, Cox, Green | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:001 | View |
4791 | CVE-2002-0399 | Candidate | Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267. | Modified (20100521) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2002:066 | Cox> Addref: RHSA-2002:138 | View |
2322 | CVE-2000-0746 | Candidate | Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities. | Proposed (20000921) | ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> Make sure both BID"s are appropriate | XF:iis-cross-site-scripting | http://xforce.iss.net/static/5156.php | Frech> XF: iis-cross-site-scripting(5156) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> A re-release of MS:MS00-060 indicates that a new variant of | this problem was discovered, but the advisory does not | provide sufficient details to distinguish it from this | candidate. A new candidate is being created, but the | description can"t be written without mentioning this CAN. | View |
1434 | CVE-1999-1454 | Candidate | Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key. | Proposed (20010912) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Foat, Wall | Christey> Looks like there might have been a re-discovery, though the | exploit is slightly different, and there is insufficient | detail to be certain that this isn"t for a different | Matrix screen saver: | BUGTRAQ:20010801 matrix screensvr(16 Bit CineMac Screen Saver Engine) - [input validation error?] | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99669949717618&w=2 | BID:3130 | URL:http://www.securityfocus.com/bid/3130 | Frech> XF:matrix-win95-password-bypass(8280) | View |
10408 | CVE-2004-1982 | Candidate | Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board"s .txt file via carriage return characters in the subject field. | Assigned (20050504) | REVIEWING(1) Christey | Christey> likely dupe with CVE-2004-2140 | View |
Page 302 of 20943, showing 5 records out of 104715 total, starting on record 1506, ending on 1510