CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6139 | CVE-2002-1757 | Candidate | PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms". | Assigned (20050621) | None (candidate not yet proposed) | View | |
71675 | CVE-2014-4379 | Candidate | An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, which allows attackers to bypass the ASLR protection mechanism via a crafted application. | Assigned (20140620) | None (candidate not yet proposed) | View | |
6395 | CVE-2002-2013 | Candidate | Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain. | Assigned (20050714) | None (candidate not yet proposed) | View | |
71931 | CVE-2014-4634 | Candidate | Unquoted Windows search path vulnerability in EMC Replication Manager through 5.5.2 and AppSync before 2.1.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | Assigned (20140624) | None (candidate not yet proposed) | View | |
6651 | CVE-2002-2269 | Candidate | Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | Assigned (20071017) | None (candidate not yet proposed) | View |
Page 19943 of 20943, showing 5 records out of 104715 total, starting on record 99711, ending on 99715