CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3013 | CVE-2001-0192 | Candidate | Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions. | Proposed (20010309) | ACCEPT(2) Baker, Lawler | MODIFY(1) Frech | NOOP(1) Ziese | Lawler> http://xmailserver.org/xmaildoc.htm | Frech> XF:xmail-ctrlserver-bo(6060) | View |
3038 | CVE-2001-0217 | Candidate | Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter. | Modified (20060609) | ACCEPT(1) Baker | MODIFY(2) Frech, Lawler | NOOP(2) Cole, Ziese | Lawler> Combine with CVE-2001-0216 | Frech> XF:webpals-library-cgi-url(6102) | View |
6873 | CVE-2003-0044 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML. | Modified (20071121) | ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | REVIEWING(1) Jones | Jones> [JHJ] XSS really "execute arbitrary web script"? | CHANGE> [Cox changed vote from NOOP to MODIFY] | Cox> "Agree with Jones, wording on effect of a XSS could be better" | Christey> I"ve been trying to devise reasonable-but-short wordings for | XSS issues and the terminology just isn"t quite there yet. This | description is clearly a failed wording, however :-) | View |
6860 | CVE-2003-0031 | Candidate | Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash). | Modified (20080207) | ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox | REVIEWING(1) Jones | Jones> [JHJ] service crash or system crash? | Christey> XF:libmcrypt-multiple-bo(10987) | URL:http://www.iss.net/security_center/static/10987.php | BID:6510 | URL:http://www.securityfocus.com/bid/6510 | View |
6871 | CVE-2003-0042 | Candidate | Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character. | Modified (20071113) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | REVIEWING(1) Jones | Jones> [JHJ] RECAST (split?) Only if vulnerability is not null character for both | View |
Page 36 of 20943, showing 5 records out of 104715 total, starting on record 176, ending on 180