CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4016  CVE-2001-1212  Candidate  Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4017  CVE-2001-1213  Candidate  The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4018  CVE-2001-1214  Candidate  manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.  Modified (20050510)  ACCEPT(1) Frech | NOOP(6) Christey, Cole, Foat, Green, Wall, Ziese  Christey> I can"t find anything about "Marcus S. Xenakis" on the web at | all, except for vulnerability reports. | CHANGE> [Green changed vote from ACCEPT to NOOP] | Green> The more I looked again today the more circular the references | were getting. And there"s no single pointer to a Marcus | Xenakis site. So, I"ll have to modify the vote to a NOOP. | Christey> A similar issue is in CVE-2002-0434, but CVE-2002-0434 is for | manual.php.  View
4019  CVE-2001-1215  Entry  Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.        View
4020  CVE-2001-1216  Candidate  Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.  Proposed (20020315)  ACCEPT(6) Cole, Foat, Frech, Green, Wall, Ziese | NOOP(1) Christey  Christey> CERT:CA-2002-08  View

Page 804 of 20943, showing 5 records out of 104715 total, starting on record 4016, ending on 4020

Actions