CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6871  CVE-2003-0042  Candidate  Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.  Modified (20071113)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | REVIEWING(1) Jones  Jones> [JHJ] RECAST (split?) Only if vulnerability is not null character for both  View
5552  CVE-2002-1168  Candidate  Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox  Green> PATCH RELEASED BY VENDOR | Christey> fix typo - "an location"  View
5610  CVE-2002-1226  Candidate  Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).  Proposed (20030317)  ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox  Christey> I need to look more closely at comments made in BID:5729, | which may be related to this issue. Also need to look at | NetBSD advisory 2002-018: | URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-018.txt.asc  View
6860  CVE-2003-0031  Candidate  Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).  Modified (20080207)  ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Christey, Cox | REVIEWING(1) Jones  Jones> [JHJ] service crash or system crash? | Christey> XF:libmcrypt-multiple-bo(10987) | URL:http://www.iss.net/security_center/static/10987.php | BID:6510 | URL:http://www.securityfocus.com/bid/6510  View
6864  CVE-2003-0035  Candidate  Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.  Modified (20080326)  ACCEPT(3) Armstrong, Cole, Green | NOOP(2) Cox, Jones  Green> APPEARS IN MANDRAKE SECURITY ADVISORY MDKSA-2003:010  View

Page 917 of 20943, showing 5 records out of 104715 total, starting on record 4581, ending on 4585

Actions