CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4894  CVE-2002-0502  Candidate  Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(3) Cox, Foat, Wall | REJECT(1) Alderson  Alderson> Too much FUD  View
4801  CVE-2002-0409  Candidate  orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.  Proposed (20020611)  ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech  Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions".  View
4161  CVE-2001-1357  Candidate  Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Alderson> Given the fact that there is limited information concerning | these "multiple" vulnerabilities mixed with the importance of time. It | appears that the information obtained so far is as sepcific as its going to | get. | Frech> XF:phpmychat-weak-input(9831)  View
4169  CVE-2001-1365  Candidate  Vulnerability in IntraGnat before 1.4.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Frech  Alderson> Even though this should be included as a candidate, I"m not sure | how one would ever actually derive a handle to this candidate | for any useful purpose other than an obscure reference.  View
4172  CVE-2001-1368  Candidate  Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.  Proposed (20020611)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Alderson  Alderson> Although the CD:VAGUE is a great way to handle issues, what do we | gain from adding an entry to describe that which might have | already been described by any number of 4 others except as a | palceholder.  View

Page 371 of 20943, showing 5 records out of 104715 total, starting on record 1851, ending on 1855

Actions