CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6414 | CVE-2002-2032 | Candidate | sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71950 | CVE-2014-4653 | Candidate | sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access. | Assigned (20140625) | None (candidate not yet proposed) | View | |
6670 | CVE-2002-2288 | Candidate | Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message. | Assigned (20071017) | None (candidate not yet proposed) | View | |
72206 | CVE-2014-4909 | Candidate | Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write. | Assigned (20140711) | None (candidate not yet proposed) | View | |
72462 | CVE-2014-5165 | Candidate | The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet. | Assigned (20140731) | None (candidate not yet proposed) | View |
Page 1122 of 20943, showing 5 records out of 104715 total, starting on record 5606, ending on 5610