CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
330 | CVE-1999-0331 | Candidate | Buffer overflow in Internet Explorer 4.0(1). | Modified (20040811) | ACCEPT(2) Baker, Northcutt | MODIFY(2) Frech, Shostack | RECAST(1) Prosser | REJECT(2) Christey, LeBlanc | Shostack> this is a high cardinality item | Prosser> needs to be more specific. | Frech> Replace reference with XF:iemk-bug (msie-bo is obsolete and a vague | duplicate) | Description (from xfdb): Some versions of Internet Explorer for Windows | contain a vulnerability that may crash the broswer when a malicious web site | contains a certain kind of URL (that begins with "mk://") with more | characters than the browser supports. | Christey> The description is too vague. | LeBlanc> too vague | Christey> Add period to the end of the description. | View |
3924 | CVE-2001-1120 | Candidate | Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates. | Modified (20040811) | ACCEPT(7) Armstrong, Baker, Cole, Foat, Frech, Green, Ziese | NOOP(1) Christey | REVIEWING(1) Wall | Green> Acknowledged by vendor in Macromedia Product Security Bulletin (MPSB01-07) issued in July, 2001 | Foat> Note that the link to the confirm should be | http://www.macomedia.com/v1/handlers/index.cfm?id=21566. | Christey> Add period to the end of the description. | View |
3725 | CVE-2001-0919 | Candidate | Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript. | Modified (20040811) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall | Frech> (ACCEPT: Task 2352) | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ie-cookie-prompt-bypass(8621) | Christey> Add period to the end of the description. | View |
165 | CVE-1999-0165 | Candidate | NFS cache poisoning. | Modified (20040811) | ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Shostack | NOOP(1) Prosser | REVIEWING(1) Christey | Shostack> need more data | Christey> need more refs | Christey> Add period to the end of the description. | View |
996 | CVE-1999-1016 | Candidate | Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. | Modified (20040811) | ACCEPT(2) Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:ms-html-table-form-dos(3246) | Frech> XF:ms-html-table-form-dos(3246) | Christey> Add period to the end of the description. | View |
Page 542 of 20943, showing 5 records out of 104715 total, starting on record 2706, ending on 2710