CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5881 | CVE-2002-1497 | Entry | Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response. | View | |||
5882 | CVE-2002-1498 | Candidate | Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "" characters. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5883 | CVE-2002-1499 | Candidate | Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5884 | CVE-2002-1500 | Candidate | Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which produces file descriptors larger than FD_SETSIZE, which are not checked by FD_SET(). | Proposed (20030317) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | View | |
5885 | CVE-2002-1501 | Entry | The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078. | View |
Page 1177 of 20943, showing 5 records out of 104715 total, starting on record 5881, ending on 5885