CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5617  CVE-2002-1233  Candidate  A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.  Modified (20050529)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox  Cox> Many vendors have included fixes for CVE-2001-0131 in their distributions | of Apache even though this has not been fixed upstream. I still believe | that this is not worthy of a separate CVE name since this is just Debian | forgetting to include their fix for CVE-2001-0131 in one of their versions, | and then correcting it.  View
71153  CVE-2014-3857  Candidate  Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.  Assigned (20140523)  None (candidate not yet proposed)    View
5873  CVE-2002-1489  Candidate  Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
71409  CVE-2014-4113  Candidate  win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View
6129  CVE-2002-1747  Candidate  Vtun 2.5b1 does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on ECB.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19147 of 20943, showing 5 records out of 104715 total, starting on record 95731, ending on 95735

Actions