CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3013  CVE-2001-0192  Candidate  Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.  Proposed (20010309)  ACCEPT(2) Baker, Lawler | MODIFY(1) Frech | NOOP(1) Ziese  Lawler> http://xmailserver.org/xmaildoc.htm | Frech> XF:xmail-ctrlserver-bo(6060)  View
3038  CVE-2001-0217  Candidate  Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.  Modified (20060609)  ACCEPT(1) Baker | MODIFY(2) Frech, Lawler | NOOP(2) Cole, Ziese  Lawler> Combine with CVE-2001-0216 | Frech> XF:webpals-library-cgi-url(6102)  View
6873  CVE-2003-0044  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.  Modified (20071121)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Cox | NOOP(1) Christey | REVIEWING(1) Jones  Jones> [JHJ] XSS really "execute arbitrary web script"? | CHANGE> [Cox changed vote from NOOP to MODIFY] | Cox> "Agree with Jones, wording on effect of a XSS could be better" | Christey> I"ve been trying to devise reasonable-but-short wordings for | XSS issues and the terminology just isn"t quite there yet. This | description is clearly a failed wording, however :-)  View
6860  CVE-2003-0031  Candidate  Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).  Modified (20080207)  ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox | REVIEWING(1) Jones  Jones> [JHJ] service crash or system crash? | Christey> XF:libmcrypt-multiple-bo(10987) | URL:http://www.iss.net/security_center/static/10987.php | BID:6510 | URL:http://www.securityfocus.com/bid/6510  View
6871  CVE-2003-0042  Candidate  Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.  Modified (20071113)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | REVIEWING(1) Jones  Jones> [JHJ] RECAST (split?) Only if vulnerability is not null character for both  View

Page 36 of 20943, showing 5 records out of 104715 total, starting on record 176, ending on 180

Actions