|
CVE-2002-1895
|
Medium
|
2002-12-31
|
No fix identified
|
No public exploit
|
The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.
|
|
CVE-2002-1882
|
High
|
2002-12-31
|
No fix identified
|
No public exploit
|
Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.
|
|
CVE-2002-1666
|
Medium
|
2002-12-31
|
No fix identified
|
No public exploit
|
Unknown vulnerability in Oracle E-Business Suite 11i.1 through 11i.6 allows remote attackers to execute unauthorized PL/SQL procedures by modifying the Oracle Applications URL.
|
|
CVE-2002-1153
|
Medium
|
2002-10-11
|
No fix identified
|
No public exploit
|
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".
|
|
CVE-2002-1640
|
Medium
|
2002-04-01
|
No fix identified
|
No public exploit
|
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet.
|
|
CVE-2002-1639
|
High
|
2002-04-01
|
No fix identified
|
No public exploit
|
Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".
|