CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4691  CVE-2002-0299  Entry  CNet CatchUp before 1.3.1 allows attackers to execute arbitrary code via a .RVP file that creates a file with an arbitrary extension (such as .BAT), which is executed during a scan.        View
4692  CVE-2002-0300  Entry  gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.        View
4693  CVE-2002-0301  Candidate  Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.  Proposed (20020502)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> XF:nfuse-user-information-disclosure(8257) | URL:http://www.iss.net/security_center/static/8257.php | Frech> XF:nfuse-user-information-disclosure(8257)  View
4694  CVE-2002-0302  Entry  The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, which could prevent some alerts from being sent in the event of an attack.        View
4695  CVE-2002-0303  Candidate  GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.  Proposed (20020502)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:groupwise-ldap-blank-password(8244)  View

Page 939 of 20943, showing 5 records out of 104715 total, starting on record 4691, ending on 4695

Actions