CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5718 | CVE-2002-1334 | Candidate | Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi. | Modified (20080226) | ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Green | View | |
5771 | CVE-2002-1387 | Candidate | The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument. | Proposed (20030317) | ACCEPT(1) Baker | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Green | Green> ACKNOWLEDGED-BY-VENDOR | View |
8490 | CVE-2004-0062 | Candidate | Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity. | Modified (20071113) | ACCEPT(1) Baker | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8486 | CVE-2004-0058 | Candidate | Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file. | Modified (20071113) | ACCEPT(1) Baker | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Green | View | |
5700 | CVE-2002-1316 | Candidate | importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315). | Modified (20071014) | ACCEPT(1) Baker | NOOP(4) Christey, Cole, Cox, Wall | REVIEWING(1) Green | Christey> fix typo: "paramatar" | View |
Page 641 of 20943, showing 5 records out of 104715 total, starting on record 3201, ending on 3205