CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4963 | CVE-2002-0572 | Candidate | FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files. | Modified (20051217) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Frech> XF:bsd-suid-apps-gain-privileges(8920) | Christey> BSA? Nope. BSD. | Take a closer look at XF:bsd-suid-apps-gain-privileges(8920), | which also references CVE-2002-0820. | Christey> Other OSes besides FreeBSD are affected. | | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | Need to more closely examine the relationship between | CVE-2002-0820 and CVE-2002-0572, especially with respect to | references. | Christey> CERT-VN:VU#809347 | URL:http://www.kb.cert.org/vuls/id/809347 | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | View |
8519 | CVE-2004-0091 | Candidate | ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called "reg_site", nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft." | Modified (20051208) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Green | View | |
8728 | CVE-2004-0300 | Candidate | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php. | Modified (20051204) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8729 | CVE-2004-0301 | Candidate | Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | Modified (20051204) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
5160 | CVE-2002-0770 | Candidate | Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password." | Modified (20051128) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View |
Page 492 of 20943, showing 5 records out of 104715 total, starting on record 2456, ending on 2460