CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2791  CVE-2000-1224  Candidate  Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.  Assigned (20050519)  None (candidate not yet proposed)    View
2792  CVE-2000-1225  Candidate  Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.  Assigned (20050621)  None (candidate not yet proposed)    View
2793  CVE-2000-1226  Candidate  Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.  Assigned (20050621)  None (candidate not yet proposed)    View
2794  CVE-2000-1227  Candidate  Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.  Assigned (20050629)  None (candidate not yet proposed)    View
2795  CVE-2000-1228  Candidate  Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 559 of 20943, showing 5 records out of 104715 total, starting on record 2791, ending on 2795

Actions