CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5407  CVE-2002-1019  Candidate  The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook for an arbitrary length of time via a modified loanMin parameter to download.asp.  Proposed (20020830)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:adobe-content-library-dos(10383)  View
5408  CVE-2002-1020  Candidate  The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available.  Proposed (20020830)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:adobe-content-bypass-loan(10385)  View
5409  CVE-2002-1021  Candidate  BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
5414  CVE-2002-1026  Candidate  Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long malformed request to TCP port 2500, possibly triggering a buffer overflow.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
5415  CVE-2002-1027  Candidate  Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> fix typo: "1the"  View

Page 49 of 20943, showing 5 records out of 104715 total, starting on record 241, ending on 245

Actions