CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1732  CVE-2000-0154  Candidate  The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.  Modified (20000403-01)  ACCEPT(1) Cole | NOOP(3) Baker, LeBlanc, Wall | REJECT(3) Christey, Frech, Levy  Christey> DUPE CVE-2000-0224 | Frech> DUPE MITRE:CVE-2000-0224; XF:sco-openserver-arc-symlink | Recommend moving BID reference to CVE-2000-0224.  View
8708  CVE-2004-0280  Candidate  Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8759  CVE-2004-0331  Candidate  Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8765  CVE-2004-0337  Candidate  Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8776  CVE-2004-0348  Candidate  SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View

Page 20278 of 20943, showing 5 records out of 104715 total, starting on record 101386, ending on 101390

Actions