CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10942 | CVE-2004-2516 | Candidate | Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10943 | CVE-2004-2517 | Candidate | myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10944 | CVE-2004-2518 | Candidate | Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10945 | CVE-2004-2519 | Candidate | Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en". | Assigned (20051025) | None (candidate not yet proposed) | View | |
10946 | CVE-2004-2520 | Candidate | POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands. | Assigned (20051025) | None (candidate not yet proposed) | View |
Page 18823 of 20943, showing 5 records out of 104715 total, starting on record 94111, ending on 94115