CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5309 | CVE-2002-0920 | Candidate | CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed. | Proposed (20020830) | ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones | View | |
4801 | CVE-2002-0409 | Candidate | orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | Proposed (20020611) | ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech | Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions". | View |
3644 | CVE-2001-0838 | Candidate | Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers execute arbitrary code via format string specifiers in the -soa command. | Proposed (20011122) | ACCEPT(2) Armstrong, Baker | MODIFY(1) Frech | NOOP(5) Bishop, Christey, Cole, Foat, Wall | Frech> XF:rwhoisd-remote-format-string(7353) | CONFIRM:http://www.securityfocus.com/archive/1/223080 | Christey> The CONFIRM reference by Andre is really this one: | BUGTRAQ:20011026 RWhoisd patched | URL:http://www.securityfocus.com/archive/1/223080 | Christey> CONFIRM:http://lists.research.netsol.com/pipermail/rwhois-announce/2001-October/000022.html | View |
8499 | CVE-2004-0071 | Candidate | Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php. | Modified (20071113) | ACCEPT(2) Armstrong, Baker | MODIFY(1) Williams | NOOP(3) Cole, Cox, Wall | Williams> contacted vendor. affects v1.2.0. fixed in v1.3.0. | http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php | http://php.amnuts.com/forums/viewtopic.php?t=70 | View |
5891 | CVE-2002-1507 | Candidate | Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports 7778 or 10777. | Proposed (20030317) | ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Cox, Wall | View |
Page 756 of 20943, showing 5 records out of 104715 total, starting on record 3776, ending on 3780