CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7050 | CVE-2003-0222 | Candidate | Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter. | Assigned (20030429) | None (candidate not yet proposed) | View | |
7051 | CVE-2003-0223 | Candidate | Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message. | Assigned (20030430) | None (candidate not yet proposed) | View | |
7052 | CVE-2003-0224 | Candidate | Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun." | Assigned (20030430) | None (candidate not yet proposed) | View | |
7053 | CVE-2003-0225 | Candidate | The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page. | Assigned (20030430) | None (candidate not yet proposed) | View | |
7054 | CVE-2003-0226 | Candidate | Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled. | Assigned (20030430) | None (candidate not yet proposed) | View |
Page 659 of 20943, showing 5 records out of 104715 total, starting on record 3291, ending on 3295