CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3901 | CVE-2001-1097 | Candidate | Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets. | Proposed (20020315) | ACCEPT(2) Cole, Frech | NOOP(5) Armstrong, Baker, Foat, Green, Wall | REVIEWING(1) Ziese | Green> TOO VAGUE | Frech> XF:cisco-ios-udp-dos(6319) should be | XF:cisco-ios-udp-dos(6913). URL is correct. | CHANGE> [Baker changed vote from REVIEWING to NOOP] | View |
3790 | CVE-2001-0985 | Candidate | shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | Green> THIS VULNERABILITY IS SUFFICIENTLY DISTINCT FROM A DIRECTORY | TRANSVERSAL TO WARRANT INCLUSION | View |
5594 | CVE-2002-1210 | Candidate | Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context. | Proposed (20030317) | ACCEPT(2) Baker, Green | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Christey | Green> THERE IS AN AMBIGOUS ACKNOWLEDGEMENT TO iDefense"s REPORTING OF THE ISSUE TO THE VENDOR | Christey> Overlap CVE-2002-0456 ? | View |
3789 | CVE-2001-0984 | Candidate | Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and promp on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords. | Proposed (20020131) | ACCEPT(2) Foat, Frech | MODIFY(1) Green | NOOP(2) Cole, Wall | Green> THE ISSUE OF WHETHER THIS IS PROGRAMMATIC OR OS RELATED SEEMS | UNSETTLED, AS DOES THE LEVEL OF PRIVILEGE THAT CAN BE OBTAINED | View |
4596 | CVE-2002-0204 | Candidate | Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command. | Proposed (20020502) | NOOP(2) Cole, Foat | REJECT(1) Wall | REVIEWING(1) Green | Green> The issue of modifying code and/or using code for purposes other than intended raises the hypothetical (albeit ridiculous) prospect of having to classify vulnerabilities within gcc, since one could develop malicious code using the compiler. | View |
Page 41 of 20943, showing 5 records out of 104715 total, starting on record 201, ending on 205