CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4616  CVE-2002-0224  Candidate  The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.  Modified (20050705)  ACCEPT(1) Green | NOOP(2) Cole, Foat | REVIEWING(1) Wall    View
4617  CVE-2002-0225  Candidate  tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4618  CVE-2002-0226  Entry  retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.        View
4619  CVE-2002-0227  Candidate  KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4620  CVE-2002-0228  Candidate  Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).  Proposed (20020502)  ACCEPT(2) Cole, Green | NOOP(1) Foat | REVIEWING(1) Wall    View

Page 924 of 20943, showing 5 records out of 104715 total, starting on record 4616, ending on 4620

Actions