CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5097 | CVE-2002-0707 | Candidate | The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow. | Modified (20071016) | ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Green, Wall | Christey> BID:5854 | URL:http://www.securityfocus.com/bid/5854 | XF:superscout-webfilter-get-dos(10242) | URL:http://www.iss.net/security_center/static/10242.php | View |
5670 | CVE-2002-1286 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user. | Modified (20071014) | ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall | View | |
5672 | CVE-2002-1288 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call. | Modified (20071014) | ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall | View | |
5673 | CVE-2002-1289 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters. | Modified (20071014) | ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall | View | |
5699 | CVE-2002-1315 | Candidate | Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316). | Modified (20071014) | ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Green | View |
Page 473 of 20943, showing 5 records out of 104715 total, starting on record 2361, ending on 2365