CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5917  CVE-2002-1533  Candidate  Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
5943  CVE-2002-1559  Candidate  Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.  Proposed (20030317)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
8789  CVE-2004-0361  Candidate  The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
5516  CVE-2002-1129  Candidate  Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.  Modified (20050610)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
8687  CVE-2004-0259  Candidate  The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View

Page 761 of 20943, showing 5 records out of 104715 total, starting on record 3801, ending on 3805

Actions