CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3856  CVE-2001-1052  Candidate  Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
69392  CVE-2014-2097  Candidate  The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted TAK (aka Tom"s lossless Audio Kompressor) data.  Assigned (20140224)  None (candidate not yet proposed)    View
4112  CVE-2001-1308  Candidate  Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
69648  CVE-2014-2353  Candidate  Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140313)  None (candidate not yet proposed)    View
4368  CVE-2001-1568  Candidate  CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 1889 of 20943, showing 5 records out of 104715 total, starting on record 9441, ending on 9445

Actions