CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4661 | CVE-2002-0269 | Candidate | Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall | Frech> XF:ie-opera-contenttype-css(8218) | View |
4662 | CVE-2002-0270 | Candidate | Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | REJECT(1) Armstrong | Frech> XF:ie-opera-contenttype-css(8218) | Christey> BID:4098 | URL:http://www.securityfocus.com/bid/4098 | View |
4663 | CVE-2002-0271 | Candidate | Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files. | Proposed (20020502) | ACCEPT(1) Cox | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | Frech> XF:gnat-temp-symlink(8178) | View |
4664 | CVE-2002-0272 | Candidate | Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request. | Proposed (20020502) | ACCEPT(2) Armstrong, Cole | MODIFY(2) Cox, Frech | NOOP(3) Christey, Foat, Wall | Cox> "possibly" is vague. It can be exploited by remote attackers | if doing network streaming. | Christey> REDHAT:RHSA-2002:078 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mpg321-long-filename-bo(10032) | View |
4665 | CVE-2002-0273 | Candidate | Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter. | Modified (20050707) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Armstrong, Cox, Foat, Wall | Frech> XF:cwmail-item-bo(8185) | View |
Page 933 of 20943, showing 5 records out of 104715 total, starting on record 4661, ending on 4665