CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4752 | CVE-2002-0360 | Candidate | Buffer overflow in Sun AnswerBook2 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long filename argument to the gettransbitmap CGI program. | Modified (20040725) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> XF:sun-answerbook2-gettransbitmap-bo(9117) | URL:http://www.iss.net/security_center/static/9117.php | BID:4784 | URL:http://www.securityfocus.com/bid/4784 | Frech> XF:sun-answerbook2-gettransbitmap-bo(9117) | View |
5027 | CVE-2002-0637 | Candidate | InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express. | Modified (20071101) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> BID:5259 | URL:http://online.securityfocus.com/bid/5259 | CONFIRM:http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionId=11948 | | According to Axel Pettinger, Solaris 3.7 build 1070 | is affected by the "boundary space (trailing)" and "Boundary | Space (prefix)" problems, but not the content-type or transfer | encoding issues. That version clearly has some overlap with | this issue, but since a different build and version number are | affected, perhaps a separate candidate needs to be created. | More information on that issue is at: | http://solutionbank.antivirus.com/solutions/solutiondetail.asp?solutionID=12142 | | Baker> http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionID=11948 | Frech> XF:interscan-viruswall-protection-bypass(9464) | View |
5071 | CVE-2002-0681 | Candidate | Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script. | Modified (20040725) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> XF:goahead-error-msg-xss(9518) | URL:http://www.iss.net/security_center/static/9518.php | BID:5198 | URL:http://www.securityfocus.com/bid/5198 | Christey> XF:goahead-encoded-directory-traversal(9519) | URL:http://www.iss.net/security_center/static/9519.php | BID:5197 | URL:http://www.securityfocus.com/bid/5197 | Frech> XF:goahead-error-msg-xss(9518) | View |
5073 | CVE-2002-0683 | Candidate | Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter. | Modified (20040818) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> XF:carello-local-file-execution(9521) | URL:http://www.iss.net/security_center/static/9521.php | BID:5192 | URL:http://www.securityfocus.com/bid/5192 | Christey> VULNWATCH:20021002 wp-02-0012: Carello 1.3 Remote File Execution (Updated 1/10/2002) | Frech> XF:carello-local-file-execution(9521) | View |
3630 | CVE-2001-0824 | Candidate | Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page. | Proposed (20011122) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall | Frech> XF:java-servlet-crosssite-scripting(6793) | This issue is associated with multiple operating | environments. | Christey> CERT-VN:VU#560659 | URL:http://www.kb.cert.org/vuls/id/560659 | MISC:http://www.kb.cert.org/vuls/id/JARL-4YZKLU | View |
Page 20312 of 20943, showing 5 records out of 104715 total, starting on record 101556, ending on 101560