CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5335  CVE-2002-0947  Entry  Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter.        View
5334  CVE-2002-0946  Entry  Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.        View
5333  CVE-2002-0945  Entry  Buffer overflow in SeaNox Devwex allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.        View
5332  CVE-2002-0944  Candidate  Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.  Modified (20030325-01)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Christey, Cox, Foat, Wall  Christey> On February 19, 2003, DeepMetrix confirmed via email that this | bug has been corrected in LiveStats 6.2.2. | | CONFIRM:http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp | | As of February 19, this URL only mentions the User-Agent bug, | but the vendor again confirmed via email that the referrer is | also addressed.  View
5331  CVE-2002-0943  Candidate  MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(5) Cole, Cox, Foat, Green, Wall  Frech> XF:shopping-cart-database-access(9816)  View

Page 19877 of 20943, showing 5 records out of 104715 total, starting on record 99381, ending on 99385

Actions