CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6116  CVE-2002-1734  Candidate  NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true".  Assigned (20050621)  None (candidate not yet proposed)    View
71652  CVE-2014-4356  Candidate  Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which allows physically proximate attackers to obtain sensitive information by reading this screen.  Assigned (20140620)  None (candidate not yet proposed)    View
6372  CVE-2002-1990  Candidate  Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.  Assigned (20050714)  None (candidate not yet proposed)    View
71908  CVE-2014-4611  Candidate  Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.  Assigned (20140623)  None (candidate not yet proposed)    View
6628  CVE-2002-2246  Candidate  Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.  Assigned (20071014)  None (candidate not yet proposed)    View

Page 18753 of 20943, showing 5 records out of 104715 total, starting on record 93761, ending on 93765

Actions