NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
74210 | CVE-2003-1138 | The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//). | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
74209 | CVE-2003-1137 | Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
74208 | CVE-2003-1136 | Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
74207 | CVE-2003-1135 | Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID. | 2 | 2.6 | Low | 2017-01-03 | 2008-09-05 | View | |
74206 | CVE-2003-1134 | Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View |
Page 16117 of 17672, showing 5 records out of 88360 total, starting on record 80581, ending on 80585