CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7050  CVE-2003-0222  Candidate  Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.  Assigned (20030429)  None (candidate not yet proposed)    View
7051  CVE-2003-0223  Candidate  Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.  Assigned (20030430)  None (candidate not yet proposed)    View
7052  CVE-2003-0224  Candidate  Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."  Assigned (20030430)  None (candidate not yet proposed)    View
7053  CVE-2003-0225  Candidate  The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.  Assigned (20030430)  None (candidate not yet proposed)    View
7054  CVE-2003-0226  Candidate  Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.  Assigned (20030430)  None (candidate not yet proposed)    View

Page 659 of 20943, showing 5 records out of 104715 total, starting on record 3291, ending on 3295

Actions