CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6246  CVE-2002-1864  Candidate  Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.  Assigned (20050629)  None (candidate not yet proposed)    View
6247  CVE-2002-1865  Candidate  Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.  Assigned (20050629)  None (candidate not yet proposed)    View
6248  CVE-2002-1866  Candidate  Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist.  Assigned (20050629)  None (candidate not yet proposed)    View
6249  CVE-2002-1867  Candidate  The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).  Assigned (20050629)  None (candidate not yet proposed)    View
6250  CVE-2002-1868  Candidate  Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 1250 of 20943, showing 5 records out of 104715 total, starting on record 6246, ending on 6250

Actions