CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3323 | CVE-2001-0506 | Entry | Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability. | View | |||
68859 | CVE-2014-1564 | Candidate | Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image. | Assigned (20140116) | None (candidate not yet proposed) | View | |
69115 | CVE-2014-1820 | Candidate | Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012 SP1 and 2014 on 64-bit platforms allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "SQL Master Data Services XSS Vulnerability." | Assigned (20140129) | None (candidate not yet proposed) | View | |
3835 | CVE-2001-1031 | Candidate | Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command. | Modified (20020228-01) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(2) Foat, Wall | View | |
69371 | CVE-2014-2076 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20140219) | None (candidate not yet proposed) | View |
Page 20547 of 20943, showing 5 records out of 104715 total, starting on record 102731, ending on 102735