CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3151  CVE-2001-0330  Entry  Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.        View
3407  CVE-2001-0594  Entry  kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.        View
3663  CVE-2001-0857  Entry  Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.        View
4175  CVE-2001-1371  Entry  The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.        View
5199  CVE-2002-0809  Entry  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.        View

Page 190 of 20943, showing 5 records out of 104715 total, starting on record 946, ending on 950

Actions