CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5601 | CVE-2002-1217 | Candidate | Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions. | Modified (20061101) | ACCEPT(3) Baker, Cole, Green | NOOP(1) Cox | REVIEWING(1) Wall | View | |
4581 | CVE-2002-0189 | Candidate | Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability. | Modified (20061101) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Christey | Christey> NOTE: As of 5/20/2002, there is a lack of clarity regarding | the details of this vulnerability and other vulnerabilities | being reported by GreyMagic and Thor Larholm. Additional | details will be added to this candidate if/when they become | available. This candidate is solely for the issue that is | being addressed by Microsoft in MS:MS02-023. Its relationship | with other reported issues is currently unproven. | | This candidate is subject to CD:VAGUE. | Christey> XF:ie-dialog-window-css(8868) | URL:http://www.iss.net/security_center/static/8868.php | Frech> XF:ie-dialog-window-css(8868) | Baker> I agree some of the information appears vague, but seems to be legitimate. | View |
5114 | CVE-2002-0724 | Candidate | Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service". | Modified (20061101) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox | Christey> XF:win-smb-packet-bo(9933) | URL:http://www.iss.net/security_center/static/9933.php | BID:5556 | URL:http://www.securityfocus.com/bid/5556 | Frech> XF:win-smb-packet-bo(9933) | View |
7419 | CVE-2003-0592 | Candidate | Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application. | Modified (20061101) | ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Cox | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Cox> Addref: REDHAT:RHSA-2004:075 | Balinsky> Acknowledgement links already in References. | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser). | View |
3326 | CVE-2001-0509 | Candidate | Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs. | Modified (20061101) | ACCEPT(7) Armstrong, Baker, Bishop, Cole, Foat, Wall, Ziese | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:ms-malformed-rpc-dos(6914) | Christey> BID:3104 | URL:http://www.securityfocus.com/bid/3104 | BUGTRAQ:20010730 Multiple Remote DoS vulnerabilities in Microsoft DCE/RPC deamons | URL:http://online.securityfocus.com/archive/1/200450 | View |
Page 485 of 20943, showing 5 records out of 104715 total, starting on record 2421, ending on 2425