CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5965 | CVE-2002-1581 | Candidate | Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter. | Assigned (20040630) | None (candidate not yet proposed) | View | |
5964 | CVE-2002-1580 | Candidate | Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347. | Assigned (20040513) | None (candidate not yet proposed) | View | |
5963 | CVE-2002-1579 | Candidate | SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error. | Assigned (20040316) | None (candidate not yet proposed) | View | |
5962 | CVE-2002-1578 | Candidate | The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is not password-protected. | Assigned (20040315) | None (candidate not yet proposed) | View | |
5961 | CVE-2002-1577 | Candidate | SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts. | Assigned (20040315) | None (candidate not yet proposed) | View |
Page 19751 of 20943, showing 5 records out of 104715 total, starting on record 98751, ending on 98755