CVE List

Id CVE No. Status Description Phase Votes Comments Actions
66829  CVE-2013-6882  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.  Assigned (20131127)  None (candidate not yet proposed)    View
1549  CVE-1999-1569  Candidate  Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server"s player limit.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | REVIEWING(1) Green    View
67085  CVE-2013-7138  Candidate  Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.  Assigned (20131218)  None (candidate not yet proposed)    View
1805  CVE-2000-0227  Candidate  The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max paremeter, which allows local users to cause a denial of service by requesting a large number of sockets.  Modified (20010910-01)  ACCEPT(8) Armstrong, Baker, Blake, Cole, Collins, Frech, Levy, Ozancin | NOOP(3) Christey, Magdych, Wall  Christey> Fix typo: "paremeter" | Magdych> I remember when this came up... seems like there were some wildly | mixed results for the exploit. | Christey> See http://marc.theaimsgroup.com/?l=bugtraq&m=95421263519558&w=2 | for Elias" summary of the mixed results. It looks like | enough people were able to replicate it that we should | include it. | Christey> Fix typo: "paremeter" | CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
67341  CVE-2013-7394  Candidate  The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types.  Assigned (20140807)  None (candidate not yet proposed)    View

Page 1038 of 20943, showing 5 records out of 104715 total, starting on record 5186, ending on 5190

Actions