CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5917 | CVE-2002-1533 | Candidate | Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a). | Proposed (20030317) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View | |
5943 | CVE-2002-1559 | Candidate | Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter. | Proposed (20030317) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View | |
8789 | CVE-2004-0361 | Candidate | The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View | |
5516 | CVE-2002-1129 | Candidate | Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument. | Modified (20050610) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View | |
8687 | CVE-2004-0259 | Candidate | The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View |
Page 761 of 20943, showing 5 records out of 104715 total, starting on record 3801, ending on 3805