CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2677  CVE-2000-1110  Candidate  document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:ibm-netdata-reveal-path(5599)  View
2681  CVE-2000-1114  Candidate  Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:ewave-jsp-source-read(5562)  View
2684  CVE-2000-1117  Candidate  The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:lotus-notes-verify-files(5565)  View
2685  CVE-2000-1118  Candidate  24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:24link-bypass-authentication(5930)  View
5742  CVE-2002-1358  Candidate  Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.  Modified (20090302)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Cox | REVIEWING(1) Wall  Frech> XF:ssh-transport-empty-lists-bo(10869)  View

Page 20324 of 20943, showing 5 records out of 104715 total, starting on record 101616, ending on 101620

Actions