CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8763  CVE-2004-0335  Candidate  LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Armstrong  Armstrong> If this is a design feature - then it should not be classed as a vulnerability.  View
5890  CVE-2002-1506  Candidate  Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall  CHANGE> [Cox changed vote from REVIEWING to NOOP]  View
5811  CVE-2002-1427  Candidate  The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5812  CVE-2002-1428  Candidate  index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5816  CVE-2002-1432  Candidate  MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View

Page 20284 of 20943, showing 5 records out of 104715 total, starting on record 101416, ending on 101420

Actions