CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5146  CVE-2002-0756  Candidate  Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.  Proposed (20020726)  ACCEPT(2) Armstrong, Cole | NOOP(4) Christey, Cox, Foat, Wall  Christey> This *might* be vendor acknowledgement: | URL:http://www.geocrawler.com/lists/3/SourceForge/12082/0/8595354/ | | However, the person who"s credited by the vendor found *TWO* | authentication-related vulnerabilities at about the same time, | and the vendor is clearly fixing "a" vulnerability. So, which | issue did the vendor fix? Which issue is the vendor | acknowledging - CVE-2002-0757 or CVE-2002-0756?  View
3748  CVE-2001-0942  Candidate  dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.  Modified (20050702)  ACCEPT(2) Armstrong, Foat | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:oracle-dbsnmp-home-validation(7645)  View
3716  CVE-2001-0910  Candidate  Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup.  Proposed (20020131)  ACCEPT(2) Armstrong, Frech | NOOP(3) Cole, Foat, Wall    View
3583  CVE-2001-0776  Candidate  Buffer overflow in DynFX MailServer version 2.10 allows remote attackers to conduct a denial of service via a long username to the POP3 service.  Proposed (20011012)  ACCEPT(2) Armstrong, Frech | NOOP(3) Cole, Foat, Wall    View
5781  CVE-2002-1397  Candidate  Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.  Modified (20071113)  ACCEPT(2) Armstrong, Green | MODIFY(1) Cox | NOOP(1) Cole  Cox> Addref: RHSA-2003:010 | Addref: RHSA-2003:001 | Addref: RHSA-2002:301  View

Page 764 of 20943, showing 5 records out of 104715 total, starting on record 3816, ending on 3820

Actions