CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10545 | CVE-2004-2119 | Candidate | Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the URL. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10544 | CVE-2004-2118 | Candidate | Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via a GET request with a long filename, possibly due to a buffer overflow. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10543 | CVE-2004-2117 | Candidate | Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP version (HTTP/1.1), or (2) a request without GET or the HTTP version. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10542 | CVE-2004-2116 | Candidate | Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .. (dot dot) in the URL. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10541 | CVE-2004-2115 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request. | Assigned (20050527) | None (candidate not yet proposed) | View |
Page 18835 of 20943, showing 5 records out of 104715 total, starting on record 94171, ending on 94175