CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6165  CVE-2002-1783  Candidate  CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.  Assigned (20050629)  None (candidate not yet proposed)    View
6164  CVE-2002-1782  Candidate  The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrary files as that user.  Assigned (20050621)  None (candidate not yet proposed)    View
6163  CVE-2002-1781  Candidate  Multiple buffer overflows in DeleGate 7.7.0 through 7.8.1 allow remote attackers to execute arbitrary code, as demonstrated using a long USER command to the POP proxy.  Assigned (20050621)  None (candidate not yet proposed)    View
6162  CVE-2002-1780  Candidate  BPM Studio Pro 4.2 by ALCATech GmbH includes a webserver that allows a remote attacker to cause a denial of service (crash) by sending a URL request for a MS-DOS device such as con. NOTE: it has been disputed that this and possibly other application-level DOS device issues stem from a bug in Windows, and as such, such applications should not be considered vulnerable themselves.  Assigned (20050621)  None (candidate not yet proposed)    View
6161  CVE-2002-1779  Candidate  The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19711 of 20943, showing 5 records out of 104715 total, starting on record 98551, ending on 98555

Actions