CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5076 | CVE-2002-0686 | Candidate | Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter. | Modified (20050328) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall | Christey> XF:iplanet-search-bo(9506) | URL:http://www.iss.net/security_center/static/9506.php | BID:4851 | URL:http://www.securityfocus.com/bid/4851 | Frech> XF:iplanet-search-bo(9506) | View |
5368 | CVE-2002-0980 | Candidate | The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL. | Modified (20050609) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Cox, Foat | REVIEWING(1) Wall | Christey> ADDREF MS:MS03-014 | URL:http://www.microsoft.com/technet/security/bulletin/ms03-014.asp | (it explicitly mentions this CAN). | | Note: MS03-014 places the blame on Outlook, not IE. | Frech> XF:ie-webfolder-script-injection(9881) | Christey> MS:MS03-014 | URL:http://www.microsoft.com/technet/security/bulletin/ms03-014.asp | | The following Bugtraq post appears to involve a different | attack vector than is currently described: | | BUGTRAQ:20030225 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part II | URL:http://www.securityfocus.com/archive/1/313174 | | *** FROM THE CVE PERSPECTIVE, THERE IS INSUFFICIENT PUBLIC | *** INFORMATION TO BE CERTAIN WHETHER THE ABOVE POST IS TRULY | *** ADDRESSED BY MS:MS03-014 OR NOT. THEREFORE IT IS NOT | *** CERTAIN WHETHER THE ABOVE REFERENCE SHOULD BE ADDED TO | *** THIS ENTRY OR NOT. | | The exploit from this Bugtraq post is being used in the | "W32/Mimail@MM" mail worm of July/August 2003. | | Also see: http://www.microsoft.com/security/incident/mimail.asp | | Also see: http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.a@mm.html | View |
2411 | CVE-2000-0842 | Candidate | The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Proposed (20001018) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall | Frech> XF:sco-help-view-files(5226) | Christey> What is the proper "spelling" for the SCO help HTTP server? | I"ve seen it as "SCOhelp" and "scohelphttp" and "SCO help HTTP" | Christey> XF:sco-help-view-files | Christey> typo - extra " | View |
2414 | CVE-2000-0845 | Candidate | kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet. | Proposed (20001018) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall | Frech> XF:du-kdebugd-write-access(5262) | Christey> This problem also allows attackers to overwrite files. | ADDREF BID:1693 | ADDREF URL:http://www.securityfocus.com/bid/1693 | ADDREF XF:du-kdebugd-write-access | ADDREF http://xforce.iss.net/static/5262.php | View |
5057 | CVE-2002-0667 | Candidate | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone. | Modified (20050610) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:pingtel-xpressa-default-password(9562) | View |
Page 630 of 20943, showing 5 records out of 104715 total, starting on record 3146, ending on 3150