CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2791 | CVE-2000-1224 | Candidate | Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others. | Assigned (20050519) | None (candidate not yet proposed) | View | |
2792 | CVE-2000-1225 | Candidate | Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program. | Assigned (20050621) | None (candidate not yet proposed) | View | |
2793 | CVE-2000-1226 | Candidate | Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan. | Assigned (20050621) | None (candidate not yet proposed) | View | |
2794 | CVE-2000-1227 | Candidate | Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back. | Assigned (20050629) | None (candidate not yet proposed) | View | |
2795 | CVE-2000-1228 | Candidate | Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 559 of 20943, showing 5 records out of 104715 total, starting on record 2791, ending on 2795