CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5292 | CVE-2002-0903 | Candidate | register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID"s, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value. | Proposed (20020830) | ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones | View | |
5294 | CVE-2002-0905 | Candidate | Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable. | Proposed (20020830) | ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones | View | |
5296 | CVE-2002-0907 | Candidate | Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-". | Proposed (20020830) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View | |
5297 | CVE-2002-0908 | Candidate | Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTPS request. | Proposed (20020830) | ACCEPT(3) Alderson, Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Jones | View | |
5298 | CVE-2002-0909 | Candidate | Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2) -f, (3) -n, (4) -D, (5) -M, or (6) -P, or via long environment variables (7) JNAMES or (8) MAILSERVER. | Proposed (20020830) | ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones | View |
Page 68 of 20943, showing 5 records out of 104715 total, starting on record 336, ending on 340