CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5076  CVE-2002-0686  Candidate  Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.  Modified (20050328)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> XF:iplanet-search-bo(9506) | URL:http://www.iss.net/security_center/static/9506.php | BID:4851 | URL:http://www.securityfocus.com/bid/4851 | Frech> XF:iplanet-search-bo(9506)  View
5368  CVE-2002-0980  Candidate  The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.  Modified (20050609)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall  Christey> ADDREF MS:MS03-014 | URL:http://www.microsoft.com/technet/security/bulletin/ms03-014.asp | (it explicitly mentions this CAN). | | Note: MS03-014 places the blame on Outlook, not IE. | Frech> XF:ie-webfolder-script-injection(9881) | Christey> MS:MS03-014 | URL:http://www.microsoft.com/technet/security/bulletin/ms03-014.asp | | The following Bugtraq post appears to involve a different | attack vector than is currently described: | | BUGTRAQ:20030225 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part II | URL:http://www.securityfocus.com/archive/1/313174 | | *** FROM THE CVE PERSPECTIVE, THERE IS INSUFFICIENT PUBLIC | *** INFORMATION TO BE CERTAIN WHETHER THE ABOVE POST IS TRULY | *** ADDRESSED BY MS:MS03-014 OR NOT. THEREFORE IT IS NOT | *** CERTAIN WHETHER THE ABOVE REFERENCE SHOULD BE ADDED TO | *** THIS ENTRY OR NOT. | | The exploit from this Bugtraq post is being used in the | "W32/Mimail@MM" mail worm of July/August 2003. | | Also see: http://www.microsoft.com/security/incident/mimail.asp | | Also see: http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.a@mm.html  View
2411  CVE-2000-0842  Candidate  The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20001018)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall  Frech> XF:sco-help-view-files(5226) | Christey> What is the proper "spelling" for the SCO help HTTP server? | I"ve seen it as "SCOhelp" and "scohelphttp" and "SCO help HTTP" | Christey> XF:sco-help-view-files | Christey> typo - extra "  View
2414  CVE-2000-0845  Candidate  kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.  Proposed (20001018)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall  Frech> XF:du-kdebugd-write-access(5262) | Christey> This problem also allows attackers to overwrite files. | ADDREF BID:1693 | ADDREF URL:http://www.securityfocus.com/bid/1693 | ADDREF XF:du-kdebugd-write-access | ADDREF http://xforce.iss.net/static/5262.php  View
5057  CVE-2002-0667  Candidate  Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.  Modified (20050610)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:pingtel-xpressa-default-password(9562)  View

Page 630 of 20943, showing 5 records out of 104715 total, starting on record 3146, ending on 3150

Actions