CVE List

Id CVE No. Status Description Phase Votes Comments Actions
330  CVE-1999-0331  Candidate  Buffer overflow in Internet Explorer 4.0(1).  Modified (20040811)  ACCEPT(2) Baker, Northcutt | MODIFY(2) Frech, Shostack | RECAST(1) Prosser | REJECT(2) Christey, LeBlanc  Shostack> this is a high cardinality item | Prosser> needs to be more specific. | Frech> Replace reference with XF:iemk-bug (msie-bo is obsolete and a vague | duplicate) | Description (from xfdb): Some versions of Internet Explorer for Windows | contain a vulnerability that may crash the broswer when a malicious web site | contains a certain kind of URL (that begins with "mk://") with more | characters than the browser supports. | Christey> The description is too vague. | LeBlanc> too vague | Christey> Add period to the end of the description.  View
3924  CVE-2001-1120  Candidate  Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.  Modified (20040811)  ACCEPT(7) Armstrong, Baker, Cole, Foat, Frech, Green, Ziese | NOOP(1) Christey | REVIEWING(1) Wall  Green> Acknowledged by vendor in Macromedia Product Security Bulletin (MPSB01-07) issued in July, 2001 | Foat> Note that the link to the confirm should be | http://www.macomedia.com/v1/handlers/index.cfm?id=21566. | Christey> Add period to the end of the description.  View
3725  CVE-2001-0919  Candidate  Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.  Modified (20040811)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall  Frech> (ACCEPT: Task 2352) | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ie-cookie-prompt-bypass(8621) | Christey> Add period to the end of the description.  View
165  CVE-1999-0165  Candidate  NFS cache poisoning.  Modified (20040811)  ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Shostack | NOOP(1) Prosser | REVIEWING(1) Christey  Shostack> need more data | Christey> need more refs | Christey> Add period to the end of the description.  View
996  CVE-1999-1016  Candidate  Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.  Modified (20040811)  ACCEPT(2) Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Frech> XF:ms-html-table-form-dos(3246) | Frech> XF:ms-html-table-form-dos(3246) | Christey> Add period to the end of the description.  View

Page 542 of 20943, showing 5 records out of 104715 total, starting on record 2706, ending on 2710

Actions