CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5642 | CVE-2002-1258 | Candidate | Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
5679 | CVE-2002-1295 | Candidate | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability." | Modified (20050610) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
5259 | CVE-2002-0869 | Candidate | Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation." | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
5532 | CVE-2002-1145 | Candidate | The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions. | Modified (20050529) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
5565 | CVE-2002-1181 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View |
Page 981 of 20943, showing 5 records out of 104715 total, starting on record 4901, ending on 4905