CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4963  CVE-2002-0572  Candidate  FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.  Modified (20051217)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Frech> XF:bsd-suid-apps-gain-privileges(8920) | Christey> BSA? Nope. BSD. | Take a closer look at XF:bsd-suid-apps-gain-privileges(8920), | which also references CVE-2002-0820. | Christey> Other OSes besides FreeBSD are affected. | | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | Need to more closely examine the relationship between | CVE-2002-0820 and CVE-2002-0572, especially with respect to | references. | Christey> CERT-VN:VU#809347 | URL:http://www.kb.cert.org/vuls/id/809347 | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2  View
8519  CVE-2004-0091  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called "reg_site", nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."  Modified (20051208)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Green    View
8728  CVE-2004-0300  Candidate  SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.  Modified (20051204)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8729  CVE-2004-0301  Candidate  Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.  Modified (20051204)  NOOP(4) Armstrong, Cole, Cox, Wall    View
5160  CVE-2002-0770  Candidate  Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."  Modified (20051128)  NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View

Page 492 of 20943, showing 5 records out of 104715 total, starting on record 2456, ending on 2460

Actions