CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3901  CVE-2001-1097  Candidate  Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.  Proposed (20020315)  ACCEPT(2) Cole, Frech | NOOP(5) Armstrong, Baker, Foat, Green, Wall | REVIEWING(1) Ziese  Green> TOO VAGUE | Frech> XF:cisco-ios-udp-dos(6319) should be | XF:cisco-ios-udp-dos(6913). URL is correct. | CHANGE> [Baker changed vote from REVIEWING to NOOP]  View
3790  CVE-2001-0985  Candidate  shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall  Green> THIS VULNERABILITY IS SUFFICIENTLY DISTINCT FROM A DIRECTORY | TRANSVERSAL TO WARRANT INCLUSION  View
5594  CVE-2002-1210  Candidate  Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.  Proposed (20030317)  ACCEPT(2) Baker, Green | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Christey  Green> THERE IS AN AMBIGOUS ACKNOWLEDGEMENT TO iDefense"s REPORTING OF THE ISSUE TO THE VENDOR | Christey> Overlap CVE-2002-0456 ?  View
3789  CVE-2001-0984  Candidate  Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and promp on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords.  Proposed (20020131)  ACCEPT(2) Foat, Frech | MODIFY(1) Green | NOOP(2) Cole, Wall  Green> THE ISSUE OF WHETHER THIS IS PROGRAMMATIC OR OS RELATED SEEMS | UNSETTLED, AS DOES THE LEVEL OF PRIVILEGE THAT CAN BE OBTAINED  View
4596  CVE-2002-0204  Candidate  Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command.  Proposed (20020502)  NOOP(2) Cole, Foat | REJECT(1) Wall | REVIEWING(1) Green  Green> The issue of modifying code and/or using code for purposes other than intended raises the hypothetical (albeit ridiculous) prospect of having to classify vulnerabilities within gcc, since one could develop malicious code using the compiler.  View

Page 41 of 20943, showing 5 records out of 104715 total, starting on record 201, ending on 205

Actions