CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5071  CVE-2002-0681  Candidate  Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.  Modified (20040725)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> XF:goahead-error-msg-xss(9518) | URL:http://www.iss.net/security_center/static/9518.php | BID:5198 | URL:http://www.securityfocus.com/bid/5198 | Christey> XF:goahead-encoded-directory-traversal(9519) | URL:http://www.iss.net/security_center/static/9519.php | BID:5197 | URL:http://www.securityfocus.com/bid/5197 | Frech> XF:goahead-error-msg-xss(9518)  View
5072  CVE-2002-0682  Entry  Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.        View
5073  CVE-2002-0683  Candidate  Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.  Modified (20040818)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> XF:carello-local-file-execution(9521) | URL:http://www.iss.net/security_center/static/9521.php | BID:5192 | URL:http://www.securityfocus.com/bid/5192 | Christey> VULNWATCH:20021002 wp-02-0012: Carello 1.3 Remote File Execution (Updated 1/10/2002) | Frech> XF:carello-local-file-execution(9521)  View
5074  CVE-2002-0684  Candidate  Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.  Modified (20040818)  ACCEPT(5) Baker, Cole, Foat, Green, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Cox> RHSA-2002:133 is CVE-2002-0651 not this one, ADDREF:RHSA-2002:167 | Christey> HP:HPSBUX0209-218 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0087.html | Frech> XF:dns-resolver-lib-bo(9432) | Christey> DELREF REDHAT:RHSA-2002:133 | Christey> DELREF REDHAT:RHSA-2002:133  View
5075  CVE-2002-0685  Entry  Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via a large, malformed mail message.        View

Page 1015 of 20943, showing 5 records out of 104715 total, starting on record 5071, ending on 5075

Actions