CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6122  CVE-2002-1740  Candidate  Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter).  Assigned (20050621)  None (candidate not yet proposed)    View
71658  CVE-2014-4362  Candidate  The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app.  Assigned (20140620)  None (candidate not yet proposed)    View
6378  CVE-2002-1996  Candidate  Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.  Assigned (20050714)  None (candidate not yet proposed)    View
71914  CVE-2014-4617  Candidate  The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.  Assigned (20140624)  None (candidate not yet proposed)    View
6634  CVE-2002-2252  Candidate  SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.  Assigned (20071014)  None (candidate not yet proposed)    View

Page 19201 of 20943, showing 5 records out of 104715 total, starting on record 96001, ending on 96005

Actions