CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102468 | CVE-2017-5648 | Candidate | While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to retain a reference to the request or response object and thereby access and/or modify information associated with another web application. | Assigned (20170129) | None (candidate not yet proposed) | View | |
2990 | CVE-2001-0169 | Entry | When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib. | View | |||
1339 | CVE-1999-1359 | Entry | When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies. | View | |||
418 | CVE-1999-0419 | Candidate | When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. | Modified (20000105-01) | ACCEPT(1) Baker | MODIFY(2) Frech, LeBlanc | REVIEWING(1) Christey | Frech> XF:smtp-4xx-error-dos | LeBlanc> - if we can find a KB or something that shows that this wasn"t just | user error, I"d vote ACCEPT. | Christey> David Lemson, Microsoft SMTP Service Program Manager, | posted a followup that said "We have confirmed this as a | problem..." | http://marc.theaimsgroup.com/?l=bugtraq&m=92171608127206&w=2 | View |
99610 | CVE-2017-2790 | Candidate | When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy. This results in a heap-based buffer overflow and can lead to code execution under the context of the application. | Assigned (20161201) | None (candidate not yet proposed) | View |
Page 216 of 20943, showing 5 records out of 104715 total, starting on record 1076, ending on 1080