|
CVE-2002-2272
|
High
|
2002-12-31
|
Mitigation candidate
|
Working exploit published
|
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
|
|
CVE-2002-1882
|
High
|
2002-12-31
|
No fix identified
|
No public exploit
|
Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.
|
|
CVE-2002-0493
|
High
|
2002-08-12
|
No exploit published
|
No public exploit
|
Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
|
|
CVE-2002-0682
|
High
|
2002-07-23
|
Mitigation candidate
|
Working exploit published
|
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
|
|
CVE-2002-1639
|
High
|
2002-04-01
|
No fix identified
|
No public exploit
|
Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".
|