CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5677  CVE-2002-1293  Candidate  The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.  Modified (20050610)  ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall  CHANGE> [Baker changed vote from MODIFY to ACCEPT]  View
5679  CVE-2002-1295  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."  Modified (20050610)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5476  CVE-2002-1089  Candidate  rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.  Modified (20050610)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:oracle-reports-information-disclosure(9628)  View
5239  CVE-2002-0849  Candidate  Linux-iSCSI iSCSI implementation installs the iscsi.conf file with world-readable permissions on some operating systems, including Red Hat Linux Limbo Beta #1, which could allow local users to gain privileges by reading the cleartext CHAP password.  Modified (20050610)  MODIFY(2) Foat, Frech | NOOP(4) Armstrong, Christey, Cole, Wall | REJECT(1) Cox  Cox> CD:EX-BETA | Foat> The candidate notes that this vulnerability pertains to "some | operating systems" and specifically mentions only Red Hat Linux Limbo Beta #1. | We found the file to be world readable on Red Hat Linux 7.2. | Frech> XF:linux-iscsi-conf-insecure(9792) | Christey> MISC:http://www.seifried.org/security/advisories/kssa-004.html  View
5514  CVE-2002-1127  Candidate  Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.  Modified (20050610)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View

Page 511 of 20943, showing 5 records out of 104715 total, starting on record 2551, ending on 2555

Actions