CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5049  CVE-2002-0659  Candidate  The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Cox | NOOP(2) Christey, Foat  Cox> ADDREF:RHSA-2002:163 RHSA-2002:184 | add "and possibly arbitrary code execution" | This issue also affects SSLeay and BSAFE SSL-C | ADDREF: http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL_Products_Security_Bulletin_Aug_8_2002.pdf | Christey> CONFIRM:http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_sca/sca_320/v320b20.htm#xtocid13 | Christey> I should probably create a separate CAN for the BSAFE issues, | unless there is a codebase relationship.  View
2671  CVE-2000-1104  Candidate  Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.  Proposed (20001219)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech  Frech> XF:iis-cross-site-scripting(5156)  View
5729  CVE-2002-1345  Candidate  Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.  Modified (20071014)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Cox  Frech> XF:ftp-client-filename-traversal(10821)  View
5490  CVE-2002-1103  Candidate  Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.  Proposed (20030317)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Cox  Frech> XF:cisco-vpn-isakmp-dos(10028)  View
5193  CVE-2002-0803  Candidate  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.  Modified (20071101)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:bugzilla-queryhelp-obtain-information(9300)  View

Page 942 of 20943, showing 5 records out of 104715 total, starting on record 4706, ending on 4710

Actions