CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5767  CVE-2002-1383  Candidate  Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.  Modified (20071220)  ACCEPT(3) Cole, Cox, Green | NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2003:001  View
4791  CVE-2002-0399  Candidate  Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.  Modified (20100521)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey  Christey> MANDRAKE:MDKSA-2002:066 | Cox> Addref: RHSA-2002:138  View
2322  CVE-2000-0746  Candidate  Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.  Proposed (20000921)  ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Christey> Make sure both BID"s are appropriate | XF:iis-cross-site-scripting | http://xforce.iss.net/static/5156.php | Frech> XF: iis-cross-site-scripting(5156) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> A re-release of MS:MS00-060 indicates that a new variant of | this problem was discovered, but the advisory does not | provide sufficient details to distinguish it from this | candidate. A new candidate is being created, but the | description can"t be written without mentioning this CAN.  View
1434  CVE-1999-1454  Candidate  Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.  Proposed (20010912)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Foat, Wall  Christey> Looks like there might have been a re-discovery, though the | exploit is slightly different, and there is insufficient | detail to be certain that this isn"t for a different | Matrix screen saver: | BUGTRAQ:20010801 matrix screensvr(16 Bit CineMac Screen Saver Engine) - [input validation error?] | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99669949717618&w=2 | BID:3130 | URL:http://www.securityfocus.com/bid/3130 | Frech> XF:matrix-win95-password-bypass(8280)  View
10408  CVE-2004-1982  Candidate  Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board"s .txt file via carriage return characters in the subject field.  Assigned (20050504)  REVIEWING(1) Christey  Christey> likely dupe with CVE-2004-2140  View

Page 302 of 20943, showing 5 records out of 104715 total, starting on record 1506, ending on 1510

Actions