CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4847  CVE-2002-0455  Candidate  IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames.  Proposed (20020611)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall  Green> INCLUSION RATIONALE IS A REASONABLE APROACH  View
70383  CVE-2014-3088  Candidate  stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.  Assigned (20140429)  None (candidate not yet proposed)    View
5103  CVE-2002-0713  Candidate  Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.  Modified (20050601)  ACCEPT(4) Armstrong, Baker, Cole, Cox | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> VULNWATCH:20020603 [VulnWatch] [DER #11] - Remotey exploitable fmt string bug in squid | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0087.html | BUGTRAQ:20020604 [DER #11] - Remotey exploitable fmt string bug in squid | URL:http://online.securityfocus.com/archive/1/275347 | | Note that this report is for the "msntauth" module, which | itself is out-of-date, but there is obviously a codebase relationship | with what"s included in the Squid distribution. | Frech> XF:squid-msnt-helper-bo(9482) | Christey> CALDERA:CSSA-2002-046.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-046.0.txt | REDHAT:RHSA-2002:051 | URL:http://rhn.redhat.com/errata/RHSA-2002-051.html | Christey> CALDERA:CSSA-2003-SCO.9  View
70639  CVE-2014-3343  Candidate  Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (DHCPv6 daemon crash) via a malformed DHCPv6 packet, aka Bug ID CSCuo59052.  Assigned (20140507)  None (candidate not yet proposed)    View
5359  CVE-2002-0971  Candidate  Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging System to bypass the VNC GUI and access the "Add new clients" dialogue box.  Modified (20050610)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Cox, Foat | REVIEWING(1) Wall  Frech> XF:vnc-win32-messaging-privileges(9979)  View

Page 19597 of 20943, showing 5 records out of 104715 total, starting on record 97981, ending on 97985

Actions