CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6122 | CVE-2002-1740 | Candidate | Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter). | Assigned (20050621) | None (candidate not yet proposed) | View | |
71658 | CVE-2014-4362 | Candidate | The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app. | Assigned (20140620) | None (candidate not yet proposed) | View | |
6378 | CVE-2002-1996 | Candidate | Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71914 | CVE-2014-4617 | Candidate | The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence. | Assigned (20140624) | None (candidate not yet proposed) | View | |
6634 | CVE-2002-2252 | Candidate | SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter. | Assigned (20071014) | None (candidate not yet proposed) | View |
Page 19201 of 20943, showing 5 records out of 104715 total, starting on record 96001, ending on 96005