CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5677 | CVE-2002-1293 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method. | Modified (20050610) | ACCEPT(2) Baker, Green | NOOP(2) Cole, Cox | REVIEWING(1) Wall | CHANGE> [Baker changed vote from MODIFY to ACCEPT] | View |
5679 | CVE-2002-1295 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability." | Modified (20050610) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
5476 | CVE-2002-1089 | Candidate | rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks. | Modified (20050610) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:oracle-reports-information-disclosure(9628) | View |
5239 | CVE-2002-0849 | Candidate | Linux-iSCSI iSCSI implementation installs the iscsi.conf file with world-readable permissions on some operating systems, including Red Hat Linux Limbo Beta #1, which could allow local users to gain privileges by reading the cleartext CHAP password. | Modified (20050610) | MODIFY(2) Foat, Frech | NOOP(4) Armstrong, Christey, Cole, Wall | REJECT(1) Cox | Cox> CD:EX-BETA | Foat> The candidate notes that this vulnerability pertains to "some | operating systems" and specifically mentions only Red Hat Linux Limbo Beta #1. | We found the file to be world readable on Red Hat Linux 7.2. | Frech> XF:linux-iscsi-conf-insecure(9792) | Christey> MISC:http://www.seifried.org/security/advisories/kssa-004.html | View |
5514 | CVE-2002-1127 | Candidate | Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter. | Modified (20050610) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View |
Page 511 of 20943, showing 5 records out of 104715 total, starting on record 2551, ending on 2555