CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5197  CVE-2002-0807  Candidate  Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.  Modified (20071101)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:bugzilla-real-name-xss(9304)  View
5201  CVE-2002-0811  Candidate  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:bugzilla-buglist-sql-injection(10144)  View
1692  CVE-2000-0114  Candidate  Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.  Proposed (20000208)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:iis-frontpage-info | Christey> Acknowledged via personal communication with Microsoft | personnel. | | May be the same as BID:1174 and/or BID:1433 (both mention | FrontPage, but one mentions shtml.exe and another mentions | shtml.dll) | Christey> [note to self: review comments by Mark Burnett] | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
6830  CVE-2003-0001  Candidate  Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.  Modified (20161205)  ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Christey> ENGARDE:ESA-20030318-009 | URL:http://www.linuxsecurity.com/advisories/engarde_advisory-2976.html | CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> Addref: RHSA-2003:088 | Christey> MANDRAKE:MDKSA-2003:039 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:039 | Frech> XF:ethernet-driver-information-leak(10996) | Christey> SGI:20030601-01-A | Christey> DEBIAN:DSA-311 | URL:http://www.debian.org/security/2003/dsa-311 | Christey> MANDRAKE:MDKSA-2003:066 | Christey> DEBIAN:DSA-332 | URL:http://www.debian.org/security/2003/dsa-332 | DEBIAN:DSA-336 | URL:http://www.debian.org/security/2003/dsa-336 | Christey> HP:HPSBUX0305-261 | URL:http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0708.1 | DEBIAN:DSA-312 | URL:http://www.debian.org/security/2003/dsa-312 | BID:6535 | URL:http://www.securityfocus.com/bid/6535 | Christey> MANDRAKE:MDKSA-2003:074 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:074 | Christey> DEBIAN:DSA-423 | URL:http://www.debian.org/security/2004/dsa-423 | Christey> BUGTRAQ:20040207 [Fwd: zyxel prestige ethernet information leakage] | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=107618991322594&w=2 | Christey> DEBIAN:DSA-442 | URL:http://www.debian.org/security/2004/dsa-442 | Christey> SGI:20030601-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20030601-01-A | Cox> Change description to say "in Linux 2.4 prior to 2.4.21" as | this was fixed in Linux 2.4.21 by changesets committed by Alan Cox on | 5th Feb 2003.  View
5245  CVE-2002-0855  Candidate  Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber"s list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.  Modified (20030325-01)  ACCEPT(3) Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(2) Christey, Foat  Cox> ADDREF:REDHAT:RHSA-2002:181 | Frech> XF:mailman-subscription-option-xss(9985) | Christey> Add to desc: "via the (1) adminpw or (2) info parameters to | the ml-name feature. | ADDREF CONECTIVA:CLA-2002:522 | | It"s not clear whether DEBIAN:DSA-147-2 addresses this issue | in addition to, or instead of, CVE-2002-0388 | Christey> BID:5298 | | Debian (Joey) has confirmed that DSA-147 also addresses this | issue.  View

Page 943 of 20943, showing 5 records out of 104715 total, starting on record 4711, ending on 4715

Actions