CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5097  CVE-2002-0707  Candidate  The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.  Modified (20071016)  ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Green, Wall  Christey> BID:5854 | URL:http://www.securityfocus.com/bid/5854 | XF:superscout-webfilter-get-dos(10242) | URL:http://www.iss.net/security_center/static/10242.php  View
5670  CVE-2002-1286  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.  Modified (20071014)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5672  CVE-2002-1288  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.  Modified (20071014)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5673  CVE-2002-1289  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters.  Modified (20071014)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall    View
5699  CVE-2002-1315  Candidate  Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).  Modified (20071014)  ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Green    View

Page 473 of 20943, showing 5 records out of 104715 total, starting on record 2361, ending on 2365

Actions