CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8763 | CVE-2004-0335 | Candidate | LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Armstrong | Armstrong> If this is a design feature - then it should not be classed as a vulnerability. | View |
5890 | CVE-2002-1506 | Candidate | Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | CHANGE> [Cox changed vote from REVIEWING to NOOP] | View |
5811 | CVE-2002-1427 | Candidate | The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5812 | CVE-2002-1428 | Candidate | index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5816 | CVE-2002-1432 | Candidate | MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View |
Page 20284 of 20943, showing 5 records out of 104715 total, starting on record 101416, ending on 101420