CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4616 | CVE-2002-0224 | Candidate | The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input. | Modified (20050705) | ACCEPT(1) Green | NOOP(2) Cole, Foat | REVIEWING(1) Wall | View | |
4617 | CVE-2002-0225 | Candidate | tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View | |
4618 | CVE-2002-0226 | Entry | retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user. | View | |||
4619 | CVE-2002-0227 | Candidate | KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View | |
4620 | CVE-2002-0228 | Candidate | Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites). | Proposed (20020502) | ACCEPT(2) Cole, Green | NOOP(1) Foat | REVIEWING(1) Wall | View |
Page 924 of 20943, showing 5 records out of 104715 total, starting on record 4616, ending on 4620