CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5718  CVE-2002-1334  Candidate  Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.  Modified (20080226)  ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Green    View
5771  CVE-2002-1387  Candidate  The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.  Proposed (20030317)  ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Green  Green> ACKNOWLEDGED-BY-VENDOR  View
8490  CVE-2004-0062  Candidate  Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.  Modified (20071113)  ACCEPT(1) Baker | NOOP(4) Armstrong, Cole, Cox, Wall    View
8486  CVE-2004-0058  Candidate  Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.  Modified (20071113)  ACCEPT(1) Baker | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Green    View
5700  CVE-2002-1316  Candidate  importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).  Modified (20071014)  ACCEPT(1) Baker | NOOP(4) Christey, Cole, Cox, Wall | REVIEWING(1) Green  Christey> fix typo: "paramatar"  View

Page 641 of 20943, showing 5 records out of 104715 total, starting on record 3201, ending on 3205

Actions