CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11023  CVE-2004-2597  Candidate  Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server"s ability to find the client"s IP address.  Assigned (20051129)  None (candidate not yet proposed)    View
76559  CVE-2014-9258  Candidate  SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.  Assigned (20141204)  None (candidate not yet proposed)    View
11279  CVE-2005-0073  Candidate  Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.  Assigned (20050114)  None (candidate not yet proposed)    View
76815  CVE-2014-9514  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150105)  None (candidate not yet proposed)    View
11535  CVE-2005-0329  Candidate  Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes .. (dot dot) sequences.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 1210 of 20943, showing 5 records out of 104715 total, starting on record 6046, ending on 6050

Actions