CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5083 | CVE-2002-0693 | Candidate | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox | View | |
4082 | CVE-2001-1278 | Candidate | Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags. | Proposed (20020502) | ACCEPT(3) Cole, Green, Wall | NOOP(1) Foat | REJECT(3) Christey, Cox, Frech | Christey> Agreed; dupe of CVE-2001-1227 | View |
5646 | CVE-2002-1262 | Candidate | Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files. | Proposed (20030317) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> NOTE: Early versions of Microsoft bulletin MS02-069 | also assigned for a "user.dir exposure" issue. This | candidate should *ONLY* be used for the external caching issue | as covered in MS:MS02-068; the "user.dir" issue is identified | by CVE-2002-1365. | View |
5676 | CVE-2002-1292 | Candidate | The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running. | Modified (20050510) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> Why is MS02-069 included here? This CAN is not mentioned in | the bulletin. | View |
5252 | CVE-2002-0862 | Candidate | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. | Modified (20061101) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> Note: CVE-2002-0828 is an earlier discovery of this candidate. | That candidate will be REJECTED in favor of this one, | which comes from a more authoritative source and is | more accurate. | View |
Page 982 of 20943, showing 5 records out of 104715 total, starting on record 4906, ending on 4910