|
CVE-2003-1123
|
High
|
2003-12-31
|
Mitigation candidate
|
Working exploit published
|
Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
|
|
CVE-2003-0896
|
High
|
2003-11-17
|
Mitigation candidate
|
Working exploit published
|
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.
|
|
CVE-2003-0866
|
Medium
|
2003-11-17
|
Mitigation candidate
|
Working exploit published
|
The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
|
|
CVE-2002-1567
|
Medium
|
2003-10-06
|
Mitigation candidate
|
Working exploit published
|
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
|
|
CVE-2002-1533
|
Medium
|
2003-03-31
|
Mitigation candidate
|
Working exploit published
|
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).
|
|
CVE-2003-0042
|
Medium
|
2003-02-07
|
Protected by RASP
|
Working exploit published
|
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
|