CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4676  CVE-2002-0284  Candidate  Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:winamp-wma-pathname-disclosure(10030)  View
4677  CVE-2002-0285  Candidate  Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers.  Modified (20050707)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:outlook-express-return-bypass(8198)  View
4678  CVE-2002-0286  Candidate  The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.  Modified (20050526)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:sitenews-getpassword-add-users(8181) | CONFIRM:http://www.securitytracker.com/alerts/2002/Feb/100349 | 8.html  View
4679  CVE-2002-0287  Entry  pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP server is not configured to use magic quotes by default.        View
4680  CVE-2002-0288  Candidate  Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:phusion-dot-directoy-traversal(8212)  View

Page 936 of 20943, showing 5 records out of 104715 total, starting on record 4676, ending on 4680

Actions