CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6975  CVE-2003-0146  Candidate  Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.  Modified (20050311)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Cox | NOOP(2) Christey, Wall  Christey> MANDRAKE:MDKSA-2003:036 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:036 | CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> REDHAT:RHSA-2003:061 | Cox> ADDREF REDHAT:RHSA-2003:060 | Christey> MANDRAKE:MDKSA-2003:036 | (as suggested by Vincent Danen of Mandrake) | Christey> CONECTIVA:CLA-2003:656  View
4402  CVE-2002-0008  Candidate  Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.  Modified (20050703)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:bugzilla-processbug-comment-spoofing(7805) | XF:bugzilla-postbug-report-spoofing(7804)  View
5328  CVE-2002-0940  Candidate  domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).  Proposed (20020830)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> Add "a different issue than CVE-2002-0939" to emphasize | difference. | Frech> XF:mscapi-csp-domesticinstall-key(10356)  View
5481  CVE-2002-1094  Candidate  Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox  Jones> Change "...via the (1) SSH banner, (2) FTP banner, or (3) an | incorrect HTTP request." to "...via (1) the SSH banner, (2) the FTP banner, | or (3) an incorrect HTTP request." | Christey> CIAC:M-119 | URL:http://www.ciac.org/ciac/bulletins/m-119.shtml  View
5601  CVE-2002-1217  Candidate  Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.  Modified (20061101)  ACCEPT(3) Baker, Cole, Green | NOOP(1) Cox | REVIEWING(1) Wall    View

Page 932 of 20943, showing 5 records out of 104715 total, starting on record 4656, ending on 4660

Actions