CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8705  CVE-2004-0277  Candidate  Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall    View
8706  CVE-2004-0278  Candidate  Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8707  CVE-2004-0279  Candidate  AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8708  CVE-2004-0280  Candidate  Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8709  CVE-2004-0281  Candidate  Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 1 of 20943, showing 5 records out of 104715 total, starting on record 1, ending on 5

<prev 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 last>>

Actions