CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6455 | CVE-2002-2073 | Candidate | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6456 | CVE-2002-2074 | Candidate | SQL injection vulnerability in Mailidx before 20020105 allows remote attackers to execute arbitrary SQL commands via the search web page. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6457 | CVE-2002-2075 | Candidate | ICQ 2001a and 2002b allows remote attackers to cause a denial of service (memory consumption and hang) via a contact message with a large contacts number. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6458 | CVE-2002-2076 | Candidate | Directory traversal vulnerability in Lil" HTTP server 2.1 and 2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6459 | CVE-2002-2077 | Candidate | The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 19115 of 20943, showing 5 records out of 104715 total, starting on record 95571, ending on 95575