CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4711  CVE-2002-0319  Candidate  Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4712  CVE-2002-0320  Candidate  Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field.  Modified (20050528)  ACCEPT(2) Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View
4713  CVE-2002-0321  Candidate  Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.  Modified (20050528)  ACCEPT(2) Cole, Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall    View
4714  CVE-2002-0322  Candidate  Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.  Proposed (20020502)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall  Frech> XF:yahooim-plaintext-password(5943)  View
4715  CVE-2002-0323  Candidate  comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:netware-webserver-directory-traversal(7726) | Christey> Need to investigate why some information sources are combining | this with a Novell web server viewcode.asp issue (e.g. the ISS | reference). | | Consider BID:3715  View

Page 943 of 20943, showing 5 records out of 104715 total, starting on record 4711, ending on 4715

Actions