CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
68875 | CVE-2014-1580 | Candidate | Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element. | Assigned (20140116) | None (candidate not yet proposed) | View | |
3595 | CVE-2001-0788 | Candidate | Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by viewing the Location header. | Proposed (20011012) | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:amlserver-reveals-path(6710) | View |
69131 | CVE-2014-1836 | Candidate | Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action. | Assigned (20140130) | None (candidate not yet proposed) | View | |
3851 | CVE-2001-1047 | Candidate | Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork. | Modified (20090819) | ACCEPT(2) Cole, Frech | MODIFY(1) Green | NOOP(3) Armstrong, Foat, Wall | CHANGE> [Green changed vote from REVIEWING to MODIFY] | Green> Should be combined with other item into a single entry | View |
69387 | CVE-2014-2092 | Candidate | Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the original disclosure also reported issues that may not cross privilege boundaries. | Assigned (20140224) | None (candidate not yet proposed) | View |
Page 1493 of 20943, showing 5 records out of 104715 total, starting on record 7461, ending on 7465