CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5909  CVE-2002-1525  Candidate  Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | RECAST(1) Christey  Christey> This should probably be SPLIT (".." and absolute path are | typically different types of bugs.)  View
71445  CVE-2014-4149  Candidate  Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View
6165  CVE-2002-1783  Candidate  CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.  Assigned (20050629)  None (candidate not yet proposed)    View
71701  CVE-2014-4405  Candidate  IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.  Assigned (20140620)  None (candidate not yet proposed)    View
6421  CVE-2002-2039  Candidate  /bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 1678 of 20943, showing 5 records out of 104715 total, starting on record 8386, ending on 8390

Actions