CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10942  CVE-2004-2516  Candidate  Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.  Assigned (20051025)  None (candidate not yet proposed)    View
10943  CVE-2004-2517  Candidate  myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.  Assigned (20051025)  None (candidate not yet proposed)    View
10944  CVE-2004-2518  Candidate  Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.  Assigned (20051025)  None (candidate not yet proposed)    View
10945  CVE-2004-2519  Candidate  Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".  Assigned (20051025)  None (candidate not yet proposed)    View
10946  CVE-2004-2520  Candidate  POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.  Assigned (20051025)  None (candidate not yet proposed)    View

Page 18823 of 20943, showing 5 records out of 104715 total, starting on record 94111, ending on 94115

Actions