CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5440  CVE-2002-1052  Candidate  Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two requests to the "aux" device.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4945  CVE-2002-0554  Candidate  webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4946  CVE-2002-0555  Candidate  IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4706  CVE-2002-0314  Candidate  fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4707  CVE-2002-0315  Candidate  fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 20241 of 20943, showing 5 records out of 104715 total, starting on record 101201, ending on 101205

Actions