CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5146 | CVE-2002-0756 | Candidate | Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies. | Proposed (20020726) | ACCEPT(2) Armstrong, Cole | NOOP(4) Christey, Cox, Foat, Wall | Christey> This *might* be vendor acknowledgement: | URL:http://www.geocrawler.com/lists/3/SourceForge/12082/0/8595354/ | | However, the person who"s credited by the vendor found *TWO* | authentication-related vulnerabilities at about the same time, | and the vendor is clearly fixing "a" vulnerability. So, which | issue did the vendor fix? Which issue is the vendor | acknowledging - CVE-2002-0757 or CVE-2002-0756? | View |
3748 | CVE-2001-0942 | Candidate | dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp. | Modified (20050702) | ACCEPT(2) Armstrong, Foat | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:oracle-dbsnmp-home-validation(7645) | View |
3716 | CVE-2001-0910 | Candidate | Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup. | Proposed (20020131) | ACCEPT(2) Armstrong, Frech | NOOP(3) Cole, Foat, Wall | View | |
3583 | CVE-2001-0776 | Candidate | Buffer overflow in DynFX MailServer version 2.10 allows remote attackers to conduct a denial of service via a long username to the POP3 service. | Proposed (20011012) | ACCEPT(2) Armstrong, Frech | NOOP(3) Cole, Foat, Wall | View | |
5781 | CVE-2002-1397 | Candidate | Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow. | Modified (20071113) | ACCEPT(2) Armstrong, Green | MODIFY(1) Cox | NOOP(1) Cole | Cox> Addref: RHSA-2003:010 | Addref: RHSA-2003:001 | Addref: RHSA-2002:301 | View |
Page 764 of 20943, showing 5 records out of 104715 total, starting on record 3816, ending on 3820