CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5309  CVE-2002-0920  Candidate  CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones    View
4801  CVE-2002-0409  Candidate  orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.  Proposed (20020611)  ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech  Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions".  View
3644  CVE-2001-0838  Candidate  Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers execute arbitrary code via format string specifiers in the -soa command.  Proposed (20011122)  ACCEPT(2) Armstrong, Baker | MODIFY(1) Frech | NOOP(5) Bishop, Christey, Cole, Foat, Wall  Frech> XF:rwhoisd-remote-format-string(7353) | CONFIRM:http://www.securityfocus.com/archive/1/223080 | Christey> The CONFIRM reference by Andre is really this one: | BUGTRAQ:20011026 RWhoisd patched | URL:http://www.securityfocus.com/archive/1/223080 | Christey> CONFIRM:http://lists.research.netsol.com/pipermail/rwhois-announce/2001-October/000022.html  View
8499  CVE-2004-0071  Candidate  Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | MODIFY(1) Williams | NOOP(3) Cole, Cox, Wall  Williams> contacted vendor. affects v1.2.0. fixed in v1.3.0. | http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php | http://php.amnuts.com/forums/viewtopic.php?t=70  View
5891  CVE-2002-1507  Candidate  Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports 7778 or 10777.  Proposed (20030317)  ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Cox, Wall    View

Page 756 of 20943, showing 5 records out of 104715 total, starting on record 3776, ending on 3780

Actions