CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5601  CVE-2002-1217  Candidate  Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.  Modified (20061101)  ACCEPT(3) Baker, Cole, Green | NOOP(1) Cox | REVIEWING(1) Wall    View
4581  CVE-2002-0189  Candidate  Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.  Modified (20061101)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Christey  Christey> NOTE: As of 5/20/2002, there is a lack of clarity regarding | the details of this vulnerability and other vulnerabilities | being reported by GreyMagic and Thor Larholm. Additional | details will be added to this candidate if/when they become | available. This candidate is solely for the issue that is | being addressed by Microsoft in MS:MS02-023. Its relationship | with other reported issues is currently unproven. | | This candidate is subject to CD:VAGUE. | Christey> XF:ie-dialog-window-css(8868) | URL:http://www.iss.net/security_center/static/8868.php | Frech> XF:ie-dialog-window-css(8868) | Baker> I agree some of the information appears vague, but seems to be legitimate.  View
5114  CVE-2002-0724  Candidate  Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".  Modified (20061101)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> XF:win-smb-packet-bo(9933) | URL:http://www.iss.net/security_center/static/9933.php | BID:5556 | URL:http://www.securityfocus.com/bid/5556 | Frech> XF:win-smb-packet-bo(9933)  View
7419  CVE-2003-0592  Candidate  Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.  Modified (20061101)  ACCEPT(5) Armstrong, Baker, Balinsky, Cole, Cox | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:web-browser-cookie-bypass(15424) | http://xforce.iss.net/xforce/xfdb/15424 | Cox> Addref: REDHAT:RHSA-2004:075 | Balinsky> Acknowledgement links already in References. | Christey> Consider whether this is really a design-level problem that applies to | the interaction between any vulnerable XSS, its associated domain, and | any web browser, because browsers enforce security boundaries at the | domain level. If so, then the "%2e%2e" problem may be a red herring, | or a single attack vector of any number of vectors. | | CVE-2003-0513, CVE-2003-0514, CVE-2003-0592, CVE-2003-0593, | and CVE-2003-0594 all cover this specific issue (each for a | different browser).  View
3326  CVE-2001-0509  Candidate  Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.  Modified (20061101)  ACCEPT(7) Armstrong, Baker, Bishop, Cole, Foat, Wall, Ziese | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:ms-malformed-rpc-dos(6914) | Christey> BID:3104 | URL:http://www.securityfocus.com/bid/3104 | BUGTRAQ:20010730 Multiple Remote DoS vulnerabilities in Microsoft DCE/RPC deamons | URL:http://online.securityfocus.com/archive/1/200450  View

Page 485 of 20943, showing 5 records out of 104715 total, starting on record 2421, ending on 2425

Actions