CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4867  CVE-2002-0475  Candidate  Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
4874  CVE-2002-0482  Candidate  Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
4641  CVE-2002-0249  Candidate  PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
4644  CVE-2002-0252  Candidate  Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header.  Modified (20090817)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View
4647  CVE-2002-0255  Candidate  The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall    View

Page 712 of 20943, showing 5 records out of 104715 total, starting on record 3556, ending on 3560

Actions