CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67059  CVE-2013-7112  Candidate  The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.  Assigned (20131216)  None (candidate not yet proposed)    View
1779  CVE-2000-0201  Entry  The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.        View
67315  CVE-2013-7368  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template parameter to (1) users/profile.php, (2) articles/index.php, or (3) admin/polls.php; (4) category_id parameter to news/submit.php; news_id parameter to (5) news/send.php or (6) comments/add.php; or (7) post_subject or (8) thread_id parameter to posts/edit.php.  Assigned (20140415)  None (candidate not yet proposed)    View
2035  CVE-2000-0457  Entry  ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.        View
67571  CVE-2014-0162  Candidate  The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or modify an image to execute arbitrary commands via a crafted location.  Assigned (20131203)  None (candidate not yet proposed)    View

Page 19904 of 20943, showing 5 records out of 104715 total, starting on record 99516, ending on 99520

Actions