CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5588  CVE-2002-1204  Candidate  Netscape Communicator 4.x allows attackers to use a link to steal a user"s preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.  Modified (20050610)  NOOP(3) Armstrong, Cole, Cox | REVIEWING(1) Wall    View
5095  CVE-2002-0705  Candidate  The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5096  CVE-2002-0706  Candidate  UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5098  CVE-2002-0708  Candidate  Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
5099  CVE-2002-0709  Candidate  SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View

Page 514 of 20943, showing 5 records out of 104715 total, starting on record 2566, ending on 2570

Actions