CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71924  CVE-2014-4627  Candidate  SQL injection vulnerability in EMC RSA Web Threat Detection 4.x before 4.6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.  Assigned (20140624)  None (candidate not yet proposed)    View
6644  CVE-2002-2262  Candidate  Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.  Assigned (20071017)  None (candidate not yet proposed)    View
72180  CVE-2014-4883  Candidate  resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.  Assigned (20140710)  None (candidate not yet proposed)    View
72436  CVE-2014-5139  Candidate  The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.  Assigned (20140730)  None (candidate not yet proposed)    View
7156  CVE-2003-0328  Candidate  EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.  Assigned (20030520)  None (candidate not yet proposed)    View

Page 19988 of 20943, showing 5 records out of 104715 total, starting on record 99936, ending on 99940

Actions