CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5909 | CVE-2002-1525 | Candidate | Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | RECAST(1) Christey | Christey> This should probably be SPLIT (".." and absolute path are | typically different types of bugs.) | View |
5659 | CVE-2002-1275 | Candidate | Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input." | Proposed (20030317) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | View | |
5917 | CVE-2002-1533 | Candidate | Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a). | Proposed (20030317) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View | |
5663 | CVE-2002-1279 | Candidate | Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option). | Proposed (20030317) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | View | |
5920 | CVE-2002-1536 | Candidate | Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) the $words or $text variables in sms.pl, or (4) the $server or $printer variables in hpled.pl. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View |
Page 21 of 20943, showing 5 records out of 104715 total, starting on record 101, ending on 105