CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6871 | CVE-2003-0042 | Candidate | Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character. | Modified (20071113) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | REVIEWING(1) Jones | Jones> [JHJ] RECAST (split?) Only if vulnerability is not null character for both | View |
6860 | CVE-2003-0031 | Candidate | Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash). | Modified (20080207) | ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox | REVIEWING(1) Jones | Jones> [JHJ] service crash or system crash? | Christey> XF:libmcrypt-multiple-bo(10987) | URL:http://www.iss.net/security_center/static/10987.php | BID:6510 | URL:http://www.securityfocus.com/bid/6510 | View |
6873 | CVE-2003-0044 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML. | Modified (20071121) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | REVIEWING(1) Jones | Jones> [JHJ] XSS really "execute arbitrary web script"? | CHANGE> [Cox changed vote from NOOP to MODIFY] | Cox> "Agree with Jones, wording on effect of a XSS could be better" | Christey> I"ve been trying to devise reasonable-but-short wordings for | XSS issues and the terminology just isn"t quite there yet. This | description is clearly a failed wording, however :-) | View |
3038 | CVE-2001-0217 | Candidate | Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter. | Modified (20060609) | ACCEPT(1) Baker | MODIFY(2) Frech, Lawler | NOOP(2) Cole, Ziese | Lawler> Combine with CVE-2001-0216 | Frech> XF:webpals-library-cgi-url(6102) | View |
3013 | CVE-2001-0192 | Candidate | Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions. | Proposed (20010309) | ACCEPT(2) Baker, Lawler | MODIFY(1) Frech | NOOP(1) Ziese | Lawler> http://xmailserver.org/xmaildoc.htm | Frech> XF:xmail-ctrlserver-bo(6060) | View |
Page 20908 of 20943, showing 5 records out of 104715 total, starting on record 104536, ending on 104540