CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6372  CVE-2002-1990  Candidate  Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.  Assigned (20050714)  None (candidate not yet proposed)    View
71908  CVE-2014-4611  Candidate  Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.  Assigned (20140623)  None (candidate not yet proposed)    View
6628  CVE-2002-2246  Candidate  Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.  Assigned (20071014)  None (candidate not yet proposed)    View
72164  CVE-2014-4867  Candidate  Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.  Assigned (20140710)  None (candidate not yet proposed)    View
6884  CVE-2003-0055  Entry  Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.        View

Page 18707 of 20943, showing 5 records out of 104715 total, starting on record 93531, ending on 93535

Actions