CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2892  CVE-2001-0071  Entry  gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.        View
3148  CVE-2001-0327  Entry  iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.        View
3404  CVE-2001-0591  Entry  Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a ".." (dot dot) attack.        View
4684  CVE-2002-0292  Entry  Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.        View
5196  CVE-2002-0806  Entry  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.        View

Page 20515 of 20943, showing 5 records out of 104715 total, starting on record 102571, ending on 102575

Actions