CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
58118 | CVE-2012-4875 | Candidate | ** DISPUTED ** Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter, allows user-assisted remote attackers to execute arbitrary code via a long file name in a PostScript document. NOTE: as of 20120314, the developer was not able to reproduce the issue and disputed it. | Assigned (20120906) | None (candidate not yet proposed) | View | |
35113 | CVE-2008-4996 | Candidate | ** DISPUTED ** init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file. NOTE: the vendor disputes this vulnerability, stating that "init is [used in] a single-user context; there"s no possibility that this is exploitable." | Assigned (20081107) | None (candidate not yet proposed) | View | |
22501 | CVE-2006-6397 | Candidate | ** DISPUTED ** Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege boundaries in normal operations. This issue is not a vulnerability. | Assigned (20061207) | None (candidate not yet proposed) | View | |
26865 | CVE-2007-3508 | Candidate | ** DISPUTED ** Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution. | Assigned (20070702) | None (candidate not yet proposed) | View | |
12960 | CVE-2005-1754 | Candidate | ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products." | Assigned (20050526) | None (candidate not yet proposed) | View |
Page 20 of 20943, showing 5 records out of 104715 total, starting on record 96, ending on 100