CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3613  CVE-2001-0807  Candidate  Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client"s hard drive via a SCRIPT tag with a SRC value that points to the text file.  Modified (20020226-01)  ACCEPT(3) Baker, Cole, Prosser | MODIFY(1) Frech | NOOP(3) Armstrong, Bishop, Foat | REVIEWING(2) Christey, Wall  Frech> XF:ie-local-file-disclosure(6688) | Prosser> Legacy product, users should have updated. | Courtesy of Microsoft Security Response Center <secure@microsoft.com>: | | IE 5 is no longer supported - so unless this repro"s on 5.01 or 5.5, we wouldn"t consider doing anything for this. | Christey> ADDREF BID:2836 | URL:http://www.securityfocus.com/bid/2836 | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
3623  CVE-2001-0817  Candidate  Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.  Modified (20020226-01)  ACCEPT(6) Armstrong, Baker, Bishop, Cole, Foat, Frech | NOOP(2) Christey, Wall  Christey> CERT:CA-2001-32 | URL:http://www.cert.org/advisories/CA-2001-32.html | CERT-VN:VU#638011 | URL:http://www.kb.cert.org/vuls/id/638011 | Christey> BID:3561 | URL:http://www.securityfocus.com/bid/3561 | CIAC:M-021 | http://www.ciac.org/ciac/bulletins/m-021.shtml  View
3641  CVE-2001-0835  Candidate  Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.  Modified (20020226-01)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Frech> XF:webalizer-html-tag-host(7350) | XF:webalizer-html-tags-keywords(7351) | Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat) | Christey> CONECTIVA:CLA-2001:435 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435  View
3651  CVE-2001-0845  Candidate  Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.  Modified (20020226-01)  ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:openvms-dms-unauthorized-access(7425)  View
3653  CVE-2001-0847  Candidate  Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.  Modified (20020226-01)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Bishop, Foat, Wall  Frech> XF:lotus-domino-navigator-access(7423)  View

Page 551 of 20943, showing 5 records out of 104715 total, starting on record 2751, ending on 2755

Actions