CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3856 | CVE-2001-1052 | Candidate | Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
69392 | CVE-2014-2097 | Candidate | The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted TAK (aka Tom"s lossless Audio Kompressor) data. | Assigned (20140224) | None (candidate not yet proposed) | View | |
4112 | CVE-2001-1308 | Candidate | Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | Proposed (20020502) | ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat | View | |
69648 | CVE-2014-2353 | Candidate | Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20140313) | None (candidate not yet proposed) | View | |
4368 | CVE-2001-1568 | Candidate | CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 1889 of 20943, showing 5 records out of 104715 total, starting on record 9441, ending on 9445