CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3635  CVE-2001-0829  Candidate  A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.  Proposed (20011122)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(6) Armstrong, Bishop, Christey, Cole, Foat, Wall  Frech> XF:java-servlet-crosssite-scripting(6793) | Christey> CERT-VN:VU#672683 | URL:http://www.kb.cert.org/vuls/id/672683  View
2905  CVE-2001-0084  Candidate  GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.  Proposed (20010202)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Christey, Cole, Prosser, Wall, Ziese  Frech> XF:gtk-module-execute-code(5832) | Christey> XF:gtk-module-execute-code | URL:http://xforce.iss.net/static/5832.php | Christey> TURBO:TLSA2001026 | URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000440.html  View
3296  CVE-2001-0479  Candidate  Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.  Proposed (20010524)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Balinsky, Cole, Renaud, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:phppgadmin-sqlphp-include-file(6484) | Balinsky> Advisory site no longer exists. There is not enough detail in the advisory, and the vendor does not acknowledge.  View
5057  CVE-2002-0667  Candidate  Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.  Modified (20050610)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:pingtel-xpressa-default-password(9562)  View
5060  CVE-2002-0670  Candidate  The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.  Modified (20050610)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:pingtel-xpressa-plaintext-passwords(9565)  View

Page 20313 of 20943, showing 5 records out of 104715 total, starting on record 101561, ending on 101565

Actions