CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3217 | CVE-2001-0399 | Candidate | Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:resin-view-javabean(6320) | View |
3222 | CVE-2001-0404 | Candidate | Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:jswdk-directory-traversal(6312) | View |
3242 | CVE-2001-0424 | Candidate | BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:bubblemon-elevate-privileges(6378) | View |
3261 | CVE-2001-0443 | Candidate | Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:qpc-popd-bo(6374) | View |
3263 | CVE-2001-0446 | Candidate | IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:ibm-wcs-view-jsp(6308) | CONFIRM:http://www-4.ibm.com/software/webservers/appserv/doc/ | v3024/EfixWeb3024.html | Comments are cryptic. | View |
Page 1128 of 20943, showing 5 records out of 104715 total, starting on record 5636, ending on 5640