CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5909  CVE-2002-1525  Candidate  Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | RECAST(1) Christey  Christey> This should probably be SPLIT (".." and absolute path are | typically different types of bugs.)  View
5659  CVE-2002-1275  Candidate  Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
5917  CVE-2002-1533  Candidate  Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
5663  CVE-2002-1279  Candidate  Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option).  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
5920  CVE-2002-1536  Candidate  Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) the $words or $text variables in sms.pl, or (4) the $server or $printer variables in hpled.pl.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View

Page 21 of 20943, showing 5 records out of 104715 total, starting on record 101, ending on 105

Actions