CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5355 | CVE-2002-0967 | Entry | Buffer overflow in eDonkey 2000 35.16.60 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long "ed2k:" URL. | View | |||
70891 | CVE-2014-3595 | Candidate | Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging. | Assigned (20140514) | None (candidate not yet proposed) | View | |
5611 | CVE-2002-1227 | Entry | PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users. | View | |||
71147 | CVE-2014-3851 | Candidate | usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the administrator password by reading this file. | Assigned (20140523) | None (candidate not yet proposed) | View | |
5867 | CVE-2002-1483 | Candidate | db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot). | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View |
Page 19268 of 20943, showing 5 records out of 104715 total, starting on record 96336, ending on 96340