CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6975 | CVE-2003-0146 | Candidate | Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows. | Modified (20050311) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Cox | NOOP(2) Christey, Wall | Christey> MANDRAKE:MDKSA-2003:036 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:036 | CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> REDHAT:RHSA-2003:061 | Cox> ADDREF REDHAT:RHSA-2003:060 | Christey> MANDRAKE:MDKSA-2003:036 | (as suggested by Vincent Danen of Mandrake) | Christey> CONECTIVA:CLA-2003:656 | View |
4402 | CVE-2002-0008 | Candidate | Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi. | Modified (20050703) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:bugzilla-processbug-comment-spoofing(7805) | XF:bugzilla-postbug-report-spoofing(7804) | View |
5328 | CVE-2002-0940 | Candidate | domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only). | Proposed (20020830) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> Add "a different issue than CVE-2002-0939" to emphasize | difference. | Frech> XF:mscapi-csp-domesticinstall-key(10356) | View |
5481 | CVE-2002-1094 | Candidate | Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request. | Proposed (20030317) | ACCEPT(3) Baker, Cole, Green | MODIFY(1) Jones | NOOP(2) Christey, Cox | Jones> Change "...via the (1) SSH banner, (2) FTP banner, or (3) an | incorrect HTTP request." to "...via (1) the SSH banner, (2) the FTP banner, | or (3) an incorrect HTTP request." | Christey> CIAC:M-119 | URL:http://www.ciac.org/ciac/bulletins/m-119.shtml | View |
5601 | CVE-2002-1217 | Candidate | Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions. | Modified (20061101) | ACCEPT(3) Baker, Cole, Green | NOOP(1) Cox | REVIEWING(1) Wall | View |
Page 932 of 20943, showing 5 records out of 104715 total, starting on record 4656, ending on 4660