CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3822  CVE-2001-1018  Candidate  Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3823  CVE-2001-1019  Candidate  Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3827  CVE-2001-1023  Candidate  Xcache 2.1 allows remote attackers to determine the absolute path of web server documents by requesting a URL that is not cached by Xcache, which returns the full pathname in the Content-PageName header.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
3837  CVE-2001-1033  Candidate  Compaq TruCluster 1.5 allows remote attackers to cause a denial of service via a port scan from a system that does not have a DNS PTR record, which causes the cluster to enter a "split-brain" state.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
4864  CVE-2002-0472  Candidate  MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall    View

Page 20090 of 20943, showing 5 records out of 104715 total, starting on record 100446, ending on 100450

Actions