CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67085 | CVE-2013-7138 | Candidate | Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter. | Assigned (20131218) | None (candidate not yet proposed) | View | |
1805 | CVE-2000-0227 | Candidate | The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max paremeter, which allows local users to cause a denial of service by requesting a large number of sockets. | Modified (20010910-01) | ACCEPT(8) Armstrong, Baker, Blake, Cole, Collins, Frech, Levy, Ozancin | NOOP(3) Christey, Magdych, Wall | Christey> Fix typo: "paremeter" | Magdych> I remember when this came up... seems like there were some wildly | mixed results for the exploit. | Christey> See http://marc.theaimsgroup.com/?l=bugtraq&m=95421263519558&w=2 | for Elias" summary of the mixed results. It looks like | enough people were able to replicate it that we should | include it. | Christey> Fix typo: "paremeter" | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
67341 | CVE-2013-7394 | Candidate | The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types. | Assigned (20140807) | None (candidate not yet proposed) | View | |
67597 | CVE-2014-0188 | Candidate | The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger. | Assigned (20131203) | None (candidate not yet proposed) | View | |
67853 | CVE-2014-0444 | Candidate | Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vulnerability than CVE-2013-5868 and CVE-2013-5871. | Assigned (20131212) | None (candidate not yet proposed) | View |
Page 1649 of 20943, showing 5 records out of 104715 total, starting on record 8241, ending on 8245