CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4894 | CVE-2002-0502 | Candidate | Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. | Proposed (20020611) | ACCEPT(2) Cole, Frech | NOOP(3) Cox, Foat, Wall | REJECT(1) Alderson | Alderson> Too much FUD | View |
4801 | CVE-2002-0409 | Candidate | orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | Proposed (20020611) | ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech | Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions". | View |
4161 | CVE-2001-1357 | Candidate | Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables. | Proposed (20020611) | ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Alderson> Given the fact that there is limited information concerning | these "multiple" vulnerabilities mixed with the importance of time. It | appears that the information obtained so far is as sepcific as its going to | get. | Frech> XF:phpmychat-weak-input(9831) | View |
4169 | CVE-2001-1365 | Candidate | Vulnerability in IntraGnat before 1.4. | Proposed (20020611) | ACCEPT(3) Alderson, Cole, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Frech | Alderson> Even though this should be included as a candidate, I"m not sure | how one would ever actually derive a handle to this candidate | for any useful purpose other than an obscure reference. | View |
4172 | CVE-2001-1368 | Candidate | Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data. | Proposed (20020611) | ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Alderson | Alderson> Although the CD:VAGUE is a great way to handle issues, what do we | gain from adding an entry to describe that which might have | already been described by any number of 4 others except as a | palceholder. | View |
Page 371 of 20943, showing 5 records out of 104715 total, starting on record 1851, ending on 1855