CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4720 | CVE-2002-0328 | Candidate | Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag. | Proposed (20020502) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:ikonboard-img-css(7460) | View |
3209 | CVE-2001-0391 | Candidate | Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:xitami-server-dos(6389) | Christey> Consider adding BID:2622 | View |
3237 | CVE-2001-0419 | Candidate | Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:oracle-appserver-ndwfn4-bo(6334) | Christey> At http://otn.oracle.com/deploy/security/alerts.htm, | in an item titled "Oracle Application Server Buffer Overflow," | Oracle says that it was "Unable to reproduce vulnerability" | View |
3091 | CVE-2001-0270 | Candidate | Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set. | Proposed (20010404) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:asx-remote-dos(6133) | Christey> A rediscovery or closely related vulnerability is in CVE-2001-0994. | View |
3114 | CVE-2001-0293 | Candidate | Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command. | Proposed (20010404) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:ftpxq-directory-traversal(6166) | Christey> Email inquiry sent to support@datawizard.net on March 10, 2002. | Christey> Acknowledgement received from rmawji@datawizard.net on March | 11, 2002: "that was fixed in the next version (2.0.94)." | View |
Page 19803 of 20943, showing 5 records out of 104715 total, starting on record 99011, ending on 99015