CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5879 | CVE-2002-1495 | Candidate | Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that are displayed in a pop-up window, and (3) certain malicious attributes within otherwise safe tags, such as onMouseOver. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View | |
5909 | CVE-2002-1525 | Candidate | Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | RECAST(1) Christey | Christey> This should probably be SPLIT (".." and absolute path are | typically different types of bugs.) | View |
5622 | CVE-2002-1238 | Candidate | Peter Sandvik"s Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/. | Modified (20050610) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Balinsky, Cox, Wall | Balinsky> Software site http://linuxstuffs.cjb.net/ is down, and no information is available on the software. Cannot confirm. | View |
5870 | CVE-2002-1486 | Candidate | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Christey, Cox, Wall | Christey> XF:trillian-irc-privmsg-bo(10143) | URL:http://www.iss.net/security_center/static/10143.php | BID:5755 | URL:http://www.securityfocus.com/bid/5755 | View |
5122 | CVE-2002-0732 | Candidate | Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments. | Proposed (20020726) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall | View |
Page 903 of 20943, showing 5 records out of 104715 total, starting on record 4511, ending on 4515