CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5355  CVE-2002-0967  Entry  Buffer overflow in eDonkey 2000 35.16.60 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long "ed2k:" URL.        View
70891  CVE-2014-3595  Candidate  Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.  Assigned (20140514)  None (candidate not yet proposed)    View
5611  CVE-2002-1227  Entry  PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.        View
71147  CVE-2014-3851  Candidate  usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the administrator password by reading this file.  Assigned (20140523)  None (candidate not yet proposed)    View
5867  CVE-2002-1483  Candidate  db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View

Page 19268 of 20943, showing 5 records out of 104715 total, starting on record 96336, ending on 96340

Actions