CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5083  CVE-2002-0693  Candidate  Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Cox    View
4082  CVE-2001-1278  Candidate  Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | NOOP(1) Foat | REJECT(3) Christey, Cox, Frech  Christey> Agreed; dupe of CVE-2001-1227  View
5646  CVE-2002-1262  Candidate  Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.  Proposed (20030317)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> NOTE: Early versions of Microsoft bulletin MS02-069 | also assigned for a "user.dir exposure" issue. This | candidate should *ONLY* be used for the external caching issue | as covered in MS:MS02-068; the "user.dir" issue is identified | by CVE-2002-1365.  View
5676  CVE-2002-1292  Candidate  The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.  Modified (20050510)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> Why is MS02-069 included here? This CAN is not mentioned in | the bulletin.  View
5252  CVE-2002-0862  Candidate  The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.  Modified (20061101)  ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox  Christey> Note: CVE-2002-0828 is an earlier discovery of this candidate. | That candidate will be REJECTED in favor of this one, | which comes from a more authoritative source and is | more accurate.  View

Page 982 of 20943, showing 5 records out of 104715 total, starting on record 4906, ending on 4910

Actions