CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70641  CVE-2014-3345  Candidate  The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503.  Assigned (20140507)  None (candidate not yet proposed)    View
5361  CVE-2002-0973  Candidate  Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.  Modified (20050529)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> BID:5493 | URL:http://online.securityfocus.com/bid/5493 | Frech> XF:freebsd-negative-system-call-bo(9903)  View
70897  CVE-2014-3601  Candidate  The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.  Assigned (20140514)  None (candidate not yet proposed)    View
5617  CVE-2002-1233  Candidate  A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.  Modified (20050529)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox  Cox> Many vendors have included fixes for CVE-2001-0131 in their distributions | of Apache even though this has not been fixed upstream. I still believe | that this is not worthy of a separate CVE name since this is just Debian | forgetting to include their fix for CVE-2001-0131 in one of their versions, | and then correcting it.  View
71153  CVE-2014-3857  Candidate  Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.  Assigned (20140523)  None (candidate not yet proposed)    View

Page 19757 of 20943, showing 5 records out of 104715 total, starting on record 98781, ending on 98785

Actions