CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6926  CVE-2003-0097  Entry  Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).        View
72462  CVE-2014-5165  Candidate  The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.  Assigned (20140731)  None (candidate not yet proposed)    View
7182  CVE-2003-0354  Candidate  Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.  Assigned (20030529)  None (candidate not yet proposed)    View
72718  CVE-2014-5421  Candidate  CareFusion Pyxis SupplyStation 8.1 with hardware test tool 1.0.16 and earlier has a hardcoded database password, which makes it easier for local users to gain privileges by leveraging cabinet access.  Assigned (20140822)  None (candidate not yet proposed)    View
7438  CVE-2003-0611  Candidate  Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2) XTOKKAETAMADIR environment variable.  Assigned (20030728)  None (candidate not yet proposed)    View

Page 1138 of 20943, showing 5 records out of 104715 total, starting on record 5686, ending on 5690

Actions