CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
77069 | CVE-2014-9768 | Candidate | ** DISPUTED ** IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor"s perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability. | Assigned (20160317) | None (candidate not yet proposed) | View | |
46585 | CVE-2010-4001 | Candidate | ** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script. | Assigned (20101019) | None (candidate not yet proposed) | View | |
53282 | CVE-2012-0039 | Candidate | ** DISPUTED ** GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application. | Assigned (20111207) | None (candidate not yet proposed) | View | |
35067 | CVE-2008-4950 | Candidate | ** DISPUTED ** gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this vulnerability, stating that "There is no sense in this bug - the script ... is called under specific cross-building environments within a chroot." | Assigned (20081105) | None (candidate not yet proposed) | View | |
10664 | CVE-2004-2238 | Candidate | ** DISPUTED ** Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability. | Assigned (20050717) | None (candidate not yet proposed) | View |
Page 20869 of 20943, showing 5 records out of 104715 total, starting on record 104341, ending on 104345