CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4641 | CVE-2002-0249 | Candidate | PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message. | Proposed (20020502) | ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
4642 | CVE-2002-0250 | Entry | Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch"s configuration and modify the administrator password. | View | |||
4643 | CVE-2002-0251 | Entry | Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d". | View | |||
4644 | CVE-2002-0252 | Candidate | Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header. | Modified (20090817) | ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
4645 | CVE-2002-0253 | Candidate | PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path. | Proposed (20020502) | ACCEPT(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall | Christey> Is this another case when PHP leaks path information by design, | as supported by "display_errors" option? Then the | vulnerability (rather, exposure) would be in the use of the | display_errors option itself, whose implications may include | this particular scenario. | CHANGE> [Cox changed vote from REVIEWING to NOOP] | View |
Page 929 of 20943, showing 5 records out of 104715 total, starting on record 4641, ending on 4645