CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4500  CVE-2002-0106  Candidate  BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
3991  CVE-2001-1187  Candidate  csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4503  CVE-2002-0109  Candidate  Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.  Proposed (20020315)  ACCEPT(2) Frech, Green | MODIFY(1) Foat | NOOP(2) Cole, Wall  Foat> Our testing showed that this vulnerabiltiy did not apply to BEFSR41 | routers.  View
3992  CVE-2001-1188  Candidate  mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fields.  Proposed (20020315)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese  Frech> XF:mailto-form-field-modify(9119)  View
3993  CVE-2001-1189  Candidate  IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View

Page 20781 of 20943, showing 5 records out of 104715 total, starting on record 103901, ending on 103905

Actions