CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71161  CVE-2014-3865  Candidate  Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname.  Assigned (20140525)  None (candidate not yet proposed)    View
5881  CVE-2002-1497  Entry  Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response.        View
71417  CVE-2014-4121  Candidate  Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View
6137  CVE-2002-1755  Candidate  tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.  Assigned (20050621)  None (candidate not yet proposed)    View
71673  CVE-2014-4377  Candidate  Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.  Assigned (20140620)  None (candidate not yet proposed)    View

Page 20390 of 20943, showing 5 records out of 104715 total, starting on record 101946, ending on 101950

Actions