CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5530  CVE-2002-1143  Candidate  Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."  Assigned (20020923)  NOOP(1) Christey  Christey> ADDREF CERT-VN:VU#899713 | URL:http://www.kb.cert.org/vuls/id/899713  View
5253  CVE-2002-0863  Candidate  Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> ADDREF CERT-VN:VU#865833 | URL:http://www.kb.cert.org/vuls/id/865833  View
2851  CVE-2001-0030  Candidate  FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.  Proposed (20010202)  ACCEPT(2) Baker, Frech | NOOP(4) Christey, Cole, Wall, Ziese  Christey> ADDREF BUGTRAQ:20001208 Foolproof Security Vulnerability | http://www.securityfocus.com/archive/1/149952  View
2097  CVE-2000-0520  Candidate  Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.  Proposed (20000712)  ACCEPT(2) Levy, Prosser | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> ADDREF BUGTRAQ:20000711 MDKSA-2000:018 dump update | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0166.html | Frech> XF:linux-restore-bo(4647) | Prosser> Add Sources: | http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-018.php3?dis=6.0 | http://www.redhat.com/support/errata/RHSA-2000-100.html  View
1687  CVE-2000-0109  Candidate  The mcsp Client Site Processor system (MultiCSP) in Standard and Poor"s ComStock is installed with several accounts that have no passwords or easily guessable default passwords.  Proposed (20000208)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(3) Baker, Christey, Wall  Christey> ADDREF BUGTRAQ:20000324 Security issues with S&P ComStock multiCSP (Linux) | http://marc.theaimsgroup.com/?l=bugtraq&m=95422382625409&w=2 | | Note: this posting was a repeat of the February 1 post, | saying that the problem still hadn"t been fixed. | Frech> XF:comstock-multicsp-passwords | Christey> ADDREF BID:1080 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=1080  View

Page 336 of 20943, showing 5 records out of 104715 total, starting on record 1676, ending on 1680

Actions