CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71952  CVE-2014-4655  Candidate  The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl calls.  Assigned (20140625)  None (candidate not yet proposed)    View
6672  CVE-2002-2290  Candidate  Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.  Assigned (20071017)  None (candidate not yet proposed)    View
72208  CVE-2014-4911  Candidate  The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.  Assigned (20140711)  None (candidate not yet proposed)    View
72464  CVE-2014-5167  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140731)  None (candidate not yet proposed)    View
7184  CVE-2003-0356  Candidate  Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.  Assigned (20030529)  None (candidate not yet proposed)    View

Page 1276 of 20943, showing 5 records out of 104715 total, starting on record 6376, ending on 6380

Actions