CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5642  CVE-2002-1258  Candidate  Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5679  CVE-2002-1295  Candidate  The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."  Modified (20050610)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5259  CVE-2002-0869  Candidate  Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5532  CVE-2002-1145  Candidate  The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.  Modified (20050529)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
5565  CVE-2002-1181  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View

Page 981 of 20943, showing 5 records out of 104715 total, starting on record 4901, ending on 4905

Actions