Show filters
36 Total Results
Displaying 31-36 of 36
Sort by:
Attacker Value
Unknown

CVE-2004-0826

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
0
Attacker Value
Unknown

CVE-2004-1815

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).
0
Attacker Value
Unknown

CVE-2003-0414

Disclosure Date: June 30, 2003 (last updated February 22, 2025)
The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.
0
Attacker Value
Unknown

CVE-2003-0411

Disclosure Date: June 30, 2003 (last updated February 22, 2025)
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.
Attacker Value
Unknown

CVE-2003-0413

Disclosure Date: June 30, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.
0
Attacker Value
Unknown

CVE-2003-0412

Disclosure Date: June 30, 2003 (last updated February 22, 2025)
Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.
0