CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1732 | CVE-2000-0154 | Candidate | The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack. | Modified (20000403-01) | ACCEPT(1) Cole | NOOP(3) Baker, LeBlanc, Wall | REJECT(3) Christey, Frech, Levy | Christey> DUPE CVE-2000-0224 | Frech> DUPE MITRE:CVE-2000-0224; XF:sco-openserver-arc-symlink | Recommend moving BID reference to CVE-2000-0224. | View |
8708 | CVE-2004-0280 | Candidate | Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8759 | CVE-2004-0331 | Candidate | Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8765 | CVE-2004-0337 | Candidate | Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8776 | CVE-2004-0348 | Candidate | SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View |
Page 20278 of 20943, showing 5 records out of 104715 total, starting on record 101386, ending on 101390