CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4176  CVE-2001-1372  Entry  Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message.        View
4432  CVE-2002-0038  Entry  Vulnerability in the cache-limiting function of the unified name service daemon (nsd) in IRIX 6.5.4 through 6.5.11 allows remote attackers to cause a denial of service by forcing the cache to fill the disk.        View
4944  CVE-2002-0553  Entry  Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.        View
5200  CVE-2002-0810  Entry  Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.        View
8784  CVE-2004-0356  Entry  Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version.        View

Page 20526 of 20943, showing 5 records out of 104715 total, starting on record 102626, ending on 102630

Actions