|
CVE-2001-1563
|
High
|
2001-12-31
|
No fix identified
|
No public exploit
|
Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.
|
|
CVE-2001-1480
|
High
|
2001-12-31
|
No fix identified
|
No public exploit
|
Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.
|
|
CVE-2001-1189
|
Medium
|
2001-12-13
|
No fix identified
|
No public exploit
|
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
|
|
CVE-2001-0824
|
High
|
2001-12-06
|
No fix identified
|
No public exploit
|
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
|
|
CVE-2001-0917
|
Medium
|
2001-11-22
|
No exploit published
|
No public exploit
|
Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.
|
|
CVE-2001-0962
|
High
|
2001-09-19
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.
|
|
CVE-2001-1008
|
High
|
2001-08-31
|
No fix identified
|
No public exploit
|
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
|
|
CVE-2001-0528
|
High
|
2001-08-14
|
No fix identified
|
No public exploit
|
Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.
|
|
CVE-2001-0590
|
Medium
|
2001-08-02
|
Mitigation candidate
|
Working exploit published
|
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
|
|
CVE-2001-0390
|
Medium
|
2001-07-02
|
Mitigation candidate
|
Working exploit published
|
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
|
|
CVE-2001-0389
|
Medium
|
2001-07-02
|
No fix identified
|
No public exploit
|
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
|
|
CVE-2000-1099
|
Medium
|
2001-01-09
|
No fix identified
|
No public exploit
|
Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.
|