CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6116 | CVE-2002-1734 | Candidate | NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true". | Assigned (20050621) | None (candidate not yet proposed) | View | |
71652 | CVE-2014-4356 | Candidate | Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which allows physically proximate attackers to obtain sensitive information by reading this screen. | Assigned (20140620) | None (candidate not yet proposed) | View | |
6372 | CVE-2002-1990 | Candidate | Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71908 | CVE-2014-4611 | Candidate | Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715. | Assigned (20140623) | None (candidate not yet proposed) | View | |
6628 | CVE-2002-2246 | Candidate | Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page. | Assigned (20071014) | None (candidate not yet proposed) | View |
Page 18753 of 20943, showing 5 records out of 104715 total, starting on record 93761, ending on 93765