CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4946  CVE-2002-0555  Candidate  IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4947  CVE-2002-0556  Candidate  Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4948  CVE-2002-0557  Candidate  Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user"s shell, or (3) atrun to change to a different user"s directory, possibly due to memory allocation failures or an incorrect call to auth_approval().  Modified (20050310)  ACCEPT(4) Baker, Cole, Frech, Green | NOOP(3) Cox, Foat, Wall    View
4949  CVE-2002-0558  Candidate  Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4950  CVE-2002-0559  Candidate  Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name.  Proposed (20020611)  ACCEPT(3) Alderson, Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> ADDREF XF:oracle-appserver-location-bo(8457)  View

Page 990 of 20943, showing 5 records out of 104715 total, starting on record 4946, ending on 4950

Actions