CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67075 | CVE-2013-7128 | Candidate | Valve Bug Reporter in the valve-bugreporter package 2.10+bsos1 in Valve SteamOS Beta stores cleartext credentials in a .valve-bugreporter.cfg file upon a Remember Credentials action, which allows local users to obtain sensitive information by reading this file. | Assigned (20131217) | None (candidate not yet proposed) | View | |
67331 | CVE-2013-7384 | Candidate | UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this issue was SPLIT from CVE-2013-6413 per ADT2 due to different vulnerability types. | Assigned (20140519) | None (candidate not yet proposed) | View | |
2051 | CVE-2000-0473 | Candidate | Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> Appears to be the same as, or similar to, CVE-2000-0011, which was | also discovered by USSR. Comments on the AnalogX web site are | decidedly sparse. In CVE-2000-0011, USSR only claims that | the vendor was informed, so is this still the same problem? | | XF:simpleserver-long-url-dos | Frech> XF:simpleserver-long-url-dos(4693) | Please review whether your BUGTRAQ:19991231 reference is correct; seems like | this is the reference to CVE-2000-0011: Buffer overflow in AnalogX | SimpleServer:WWW HTTP server allows remote attackers to execute commands via | a long GET request. They are subtle; almost the only thing that changed was | the version. | A possible reference is "Remote DoS attack in AnalogX SimpleServer WWW | Version 1.05 Vulnerability" at http://www.ussrback.com/labs45.html. | View |
67587 | CVE-2014-0178 | Candidate | Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request. | Assigned (20131203) | None (candidate not yet proposed) | View | |
67843 | CVE-2014-0434 | Candidate | Unspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Oracle Supply Chain Products Suite 6.0, 6.1, and 6.1.1 allows remote attackers to affect integrity via unknown vectors related to Installation. | Assigned (20131212) | None (candidate not yet proposed) | View |
Page 242 of 20943, showing 5 records out of 104715 total, starting on record 1206, ending on 1210