CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4844 | CVE-2002-0452 | Candidate | Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than intended and exploit vulnerabilities that would otherwise be inaccessible. | Proposed (20020611) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall | Green> INCLUSION | View |
3930 | CVE-2001-1126 | Candidate | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. | Proposed (20020315) | ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall | Green> IN ONE VERSION, BUT NOT IN THE OTHER | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Concur with Analysis, this should be split. The DoS would | include all versions of LiveUpdate, 1.4.x through 1.6.x. The | potential for unauthorized code execution only impacts 1.4.x through | 1.5.x. | View |
3931 | CVE-2001-1127 | Candidate | Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4) orarx, (5) sqlcpp, (6) _probrkr, (7) _sqlschema and (8) _sqldump. | Proposed (20020315) | ACCEPT(3) Cole, Frech, Green | NOOP(4) Armstrong, Foat, Wall, Ziese | Green> IN ONE VERSION, BUT NOT IN THE OTHER | View |
3775 | CVE-2001-0970 | Candidate | Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script. | Modified (20071006) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Green> HAS-INDEPENDENT-CONFIRMATION | Frech> XF:tdforum-cross-site-scripting(7009) | View |
4022 | CVE-2001-1218 | Candidate | Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window. | Proposed (20020315) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | Green> From scanning MS-TechNet there are sufficient similar conundrums | between Solaris and IE to assume that this rings true | Frech> XF:ie-unix-chinchar-dos(9121) | View |
Page 44 of 20943, showing 5 records out of 104715 total, starting on record 216, ending on 220