CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5292  CVE-2002-0903  Candidate  register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID"s, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones    View
5294  CVE-2002-0905  Candidate  Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones    View
5296  CVE-2002-0907  Candidate  Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-".  Proposed (20020830)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
5297  CVE-2002-0908  Candidate  Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTPS request.  Proposed (20020830)  ACCEPT(3) Alderson, Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Jones    View
5298  CVE-2002-0909  Candidate  Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2) -f, (3) -n, (4) -D, (5) -M, or (6) -P, or via long environment variables (7) JNAMES or (8) MAILSERVER.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones    View

Page 68 of 20943, showing 5 records out of 104715 total, starting on record 336, ending on 340

Actions