CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3281  CVE-2001-0464  Candidate  Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.  Modified (20070307)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:cyberscheduler-timezone-bo(6401) | Christey> BUGTRAQ:20010420 Apology: Advisory numbering confusion | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98779423227844&w=2  View
4954  CVE-2002-0563  Candidate  The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.  Modified (20070207)  ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:oracle-appserver-apache-services(8455)  View
1516  CVE-1999-1536  Candidate  .sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.  Modified (20070207)  NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech  Frech> (ACCEPT; Task 2356)  View
8713  CVE-2004-0285  Candidate  PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.  Modified (20070123)  NOOP(4) Armstrong, Cole, Cox, Wall    View
4614  CVE-2002-0222  Candidate  Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.  Modified (20070122)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View

Page 477 of 20943, showing 5 records out of 104715 total, starting on record 2381, ending on 2385

Actions