CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6630  CVE-2002-2248  Candidate  Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.  Assigned (20071014)  None (candidate not yet proposed)    View
6629  CVE-2002-2247  Candidate  The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.  Assigned (20071014)  None (candidate not yet proposed)    View
6628  CVE-2002-2246  Candidate  Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.  Assigned (20071014)  None (candidate not yet proposed)    View
6627  CVE-2002-2245  Candidate  ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.  Assigned (20071014)  None (candidate not yet proposed)    View
6626  CVE-2002-2244  Candidate  Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.  Assigned (20071014)  None (candidate not yet proposed)    View

Page 19618 of 20943, showing 5 records out of 104715 total, starting on record 98086, ending on 98090

Actions