CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71161  CVE-2014-3865  Candidate  Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname.  Assigned (20140525)  None (candidate not yet proposed)    View
71417  CVE-2014-4121  Candidate  Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View
6137  CVE-2002-1755  Candidate  tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.  Assigned (20050621)  None (candidate not yet proposed)    View
71673  CVE-2014-4377  Candidate  Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.  Assigned (20140620)  None (candidate not yet proposed)    View
6393  CVE-2002-2011  Candidate  Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 20373 of 20943, showing 5 records out of 104715 total, starting on record 101861, ending on 101865

Actions