CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4891  CVE-2002-0499  Candidate  The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.  Proposed (20020611)  ACCEPT(3) Cole, Foat, Frech | NOOP(3) Armstrong, Cox, Wall | REVIEWING(1) Christey  CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | CHANGE> [Cox changed vote from ACCEPT to NOOP] | Christey> Need to investigate this more... is it the responsibility | of the kernel to address this, or the application | programmer?  View
4892  CVE-2002-0500  Candidate  Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(3) Armstrong, Cox, Foat | REVIEWING(1) Wall    View
4893  CVE-2002-0501  Entry  Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.        View
4894  CVE-2002-0502  Candidate  Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(3) Cox, Foat, Wall | REJECT(1) Alderson  Alderson> Too much FUD  View
4895  CVE-2002-0503  Candidate  Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View

Page 979 of 20943, showing 5 records out of 104715 total, starting on record 4891, ending on 4895

Actions