CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8705 | CVE-2004-0277 | Candidate | Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | NOOP(2) Cox, Wall | View | |
8706 | CVE-2004-0278 | Candidate | Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8707 | CVE-2004-0279 | Candidate | AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8708 | CVE-2004-0280 | Candidate | Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8709 | CVE-2004-0281 | Candidate | Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View |
Page 1 of 20943, showing 5 records out of 104715 total, starting on record 1, ending on 5