CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4622  CVE-2002-0230  Candidate  Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.  Proposed (20020502)  ACCEPT(2) Cole, Green | NOOP(2) Foat, Wall | RECAST(1) Christey  Christey> XF:faqomatic-cgi-css(8066) | URL:http://www.iss.net/security_center/static/8066.php | BID:4023 | URL:http://www.securityfocus.com/bid/4023 | | A similar issue was discovered a few months afterward in the | "file" parameter, but it was already fixed by the vendor along | with the cmd parameter. Thus CD:SF-LOC suggests combining | these into a single item. | CONFIRM:http://sourceforge.net/mailarchive/forum.php?thread_id=477665&forum_id=6367 | BID:4565 | URL:http://www.securityfocus.com/bid/4565  View
4111  CVE-2001-1307  Candidate  Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
4112  CVE-2001-1308  Candidate  Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
4624  CVE-2002-0232  Candidate  Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4113  CVE-2001-1309  Candidate  Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(3) Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View

Page 20794 of 20943, showing 5 records out of 104715 total, starting on record 103966, ending on 103970

Actions