CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3613 | CVE-2001-0807 | Candidate | Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client"s hard drive via a SCRIPT tag with a SRC value that points to the text file. | Modified (20020226-01) | ACCEPT(3) Baker, Cole, Prosser | MODIFY(1) Frech | NOOP(3) Armstrong, Bishop, Foat | REVIEWING(2) Christey, Wall | Frech> XF:ie-local-file-disclosure(6688) | Prosser> Legacy product, users should have updated. | Courtesy of Microsoft Security Response Center <secure@microsoft.com>: | | IE 5 is no longer supported - so unless this repro"s on 5.01 or 5.5, we wouldn"t consider doing anything for this. | Christey> ADDREF BID:2836 | URL:http://www.securityfocus.com/bid/2836 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
3623 | CVE-2001-0817 | Candidate | Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request. | Modified (20020226-01) | ACCEPT(6) Armstrong, Baker, Bishop, Cole, Foat, Frech | NOOP(2) Christey, Wall | Christey> CERT:CA-2001-32 | URL:http://www.cert.org/advisories/CA-2001-32.html | CERT-VN:VU#638011 | URL:http://www.kb.cert.org/vuls/id/638011 | Christey> BID:3561 | URL:http://www.securityfocus.com/bid/3561 | CIAC:M-021 | http://www.ciac.org/ciac/bulletins/m-021.shtml | View |
3641 | CVE-2001-0835 | Candidate | Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup. | Modified (20020226-01) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:webalizer-html-tag-host(7350) | XF:webalizer-html-tags-keywords(7351) | Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat) | Christey> CONECTIVA:CLA-2001:435 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435 | View |
3651 | CVE-2001-0845 | Candidate | Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources. | Modified (20020226-01) | ACCEPT(5) Armstrong, Baker, Bishop, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:openvms-dms-unauthorized-access(7425) | View |
3653 | CVE-2001-0847 | Candidate | Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID. | Modified (20020226-01) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(3) Bishop, Foat, Wall | Frech> XF:lotus-domino-navigator-access(7423) | View |
Page 551 of 20943, showing 5 records out of 104715 total, starting on record 2751, ending on 2755