CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3118  CVE-2001-0297  Candidate  Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.  Proposed (20010404)  ACCEPT(1) Cole | NOOP(2) Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop  Frech> Dupe of CVE-2001-0186  View
8712  CVE-2004-0284  Candidate  Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Christey, Cox | REVIEWING(1) Wall  Christey> MISC:http://www.acrossecurity.com/aspr/ASPR-2004-01-20-1-PUB.txt  View
8708  CVE-2004-0280  Candidate  Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8759  CVE-2004-0331  Candidate  Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8765  CVE-2004-0337  Candidate  Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View

Page 663 of 20943, showing 5 records out of 104715 total, starting on record 3311, ending on 3315

Actions