CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5197 | CVE-2002-0807 | Candidate | Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi. | Modified (20071101) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-real-name-xss(9304) | View |
5201 | CVE-2002-0811 | Candidate | Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:bugzilla-buglist-sql-injection(10144) | View |
1692 | CVE-2000-0114 | Candidate | Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. | Proposed (20000208) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-frontpage-info | Christey> Acknowledged via personal communication with Microsoft | personnel. | | May be the same as BID:1174 and/or BID:1433 (both mention | FrontPage, but one mentions shtml.exe and another mentions | shtml.dll) | Christey> [note to self: review comments by Mark Burnett] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
6830 | CVE-2003-0001 | Candidate | Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak. | Modified (20161205) | ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey | Christey> ENGARDE:ESA-20030318-009 | URL:http://www.linuxsecurity.com/advisories/engarde_advisory-2976.html | CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> Addref: RHSA-2003:088 | Christey> MANDRAKE:MDKSA-2003:039 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:039 | Frech> XF:ethernet-driver-information-leak(10996) | Christey> SGI:20030601-01-A | Christey> DEBIAN:DSA-311 | URL:http://www.debian.org/security/2003/dsa-311 | Christey> MANDRAKE:MDKSA-2003:066 | Christey> DEBIAN:DSA-332 | URL:http://www.debian.org/security/2003/dsa-332 | DEBIAN:DSA-336 | URL:http://www.debian.org/security/2003/dsa-336 | Christey> HP:HPSBUX0305-261 | URL:http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0708.1 | DEBIAN:DSA-312 | URL:http://www.debian.org/security/2003/dsa-312 | BID:6535 | URL:http://www.securityfocus.com/bid/6535 | Christey> MANDRAKE:MDKSA-2003:074 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:074 | Christey> DEBIAN:DSA-423 | URL:http://www.debian.org/security/2004/dsa-423 | Christey> BUGTRAQ:20040207 [Fwd: zyxel prestige ethernet information leakage] | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107618991322594&w=2 | Christey> DEBIAN:DSA-442 | URL:http://www.debian.org/security/2004/dsa-442 | Christey> SGI:20030601-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20030601-01-A | Cox> Change description to say "in Linux 2.4 prior to 2.4.21" as | this was fixed in Linux 2.4.21 by changesets committed by Alan Cox on | 5th Feb 2003. | View |
5245 | CVE-2002-0855 | Candidate | Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber"s list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature. | Modified (20030325-01) | ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat | Cox> ADDREF:REDHAT:RHSA-2002:181 | Frech> XF:mailman-subscription-option-xss(9985) | Christey> Add to desc: "via the (1) adminpw or (2) info parameters to | the ml-name feature. | ADDREF CONECTIVA:CLA-2002:522 | | It"s not clear whether DEBIAN:DSA-147-2 addresses this issue | in addition to, or instead of, CVE-2002-0388 | Christey> BID:5298 | | Debian (Joey) has confirmed that DSA-147 also addresses this | issue. | View |
Page 943 of 20943, showing 5 records out of 104715 total, starting on record 4711, ending on 4715