CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5205 | CVE-2002-0815 | Candidate | The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server"s parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain. | Proposed (20020830) | ACCEPT(1) Baker | NOOP(4) Cole, Cox, Foat, Wall | View | |
5461 | CVE-2002-1073 | Candidate | Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password. | Proposed (20020830) | ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Foat, Wall | Christey> The vendor confirmed this issue via email on August 30: | "The vulnerability report was correct. The problem are fixed in the | mercur control service version <4.02.01>. This version of the mercur | control service are integrated in the current download version of | Mercur Mailserver 4.2." | View |
5462 | CVE-2002-1075 | Candidate | Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers. | Proposed (20020830) | NOOP(4) Cole, Cox, Foat, Wall | View | |
5464 | CVE-2002-1077 | Candidate | IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field. | Proposed (20020830) | NOOP(4) Cole, Cox, Foat, Wall | View | |
5209 | CVE-2002-0819 | Candidate | Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function. | Proposed (20020830) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Cox, Wall | REJECT(1) Foat | Foat> Artsd was supposedly vulnerable to a format string vulneraibity | resulting in elevated privileges because it called command (artscontrol) and was | installed suid root. The problem was supposed to affect Red Hat 7.2. We looked | at two different install of 7.2, neither of which had artsd nor artscontrol | installed suid root. | Frech> XF:artswrapper-artsd-format-string(9813) | View |
Page 56 of 20943, showing 5 records out of 104715 total, starting on record 276, ending on 280