CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6775 | CVE-2002-2393 | Candidate | Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands. | Assigned (20071031) | None (candidate not yet proposed) | View | |
6774 | CVE-2002-2392 | Candidate | Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code. | Assigned (20071031) | None (candidate not yet proposed) | View | |
6773 | CVE-2002-2391 | Candidate | SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter. | Assigned (20071031) | None (candidate not yet proposed) | View | |
6772 | CVE-2002-2390 | Candidate | Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request. | Assigned (20071031) | None (candidate not yet proposed) | View | |
6771 | CVE-2002-2389 | Candidate | TheServer 1.74 web server stores server.ini under the web document root with insufficient access control, which allows remote attackers to obtain cleartext passwords and gain access to server log files. | Assigned (20071031) | None (candidate not yet proposed) | View |
Page 19589 of 20943, showing 5 records out of 104715 total, starting on record 97941, ending on 97945