CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4851  CVE-2002-0459  Candidate  Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.  Proposed (20020611)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4852  CVE-2002-0460  Candidate  Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are not properly freed by SSHd.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REVIEWING(1) Green    View
4853  CVE-2002-0461  Candidate  Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.  Proposed (20020611)  ACCEPT(2) Foat, Frech | NOOP(4) Cole, Cox, Green, Wall    View
4854  CVE-2002-0462  Entry  bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled.        View
4855  CVE-2002-0463  Entry  home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message.        View

Page 971 of 20943, showing 5 records out of 104715 total, starting on record 4851, ending on 4855

Actions