CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6800 | CVE-2002-2418 | Candidate | Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page. | Assigned (20071101) | None (candidate not yet proposed) | View | |
6799 | CVE-2002-2417 | Candidate | acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges. | Assigned (20071101) | None (candidate not yet proposed) | View | |
6798 | CVE-2002-2416 | Candidate | Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request. | Assigned (20071101) | None (candidate not yet proposed) | View | |
6797 | CVE-2002-2415 | Candidate | Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service. | Assigned (20071101) | None (candidate not yet proposed) | View | |
6796 | CVE-2002-2414 | Candidate | Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash). | Assigned (20071101) | None (candidate not yet proposed) | View |
Page 19584 of 20943, showing 5 records out of 104715 total, starting on record 97916, ending on 97920