CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
38186 | CVE-2009-0751 | Candidate | Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers. | Assigned (20090302) | None (candidate not yet proposed) | View | |
41930 | CVE-2009-4495 | Candidate | Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window"s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | Assigned (20091230) | None (candidate not yet proposed) | View | |
88420 | CVE-2016-1601 | Candidate | yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to have unspecified impact via unknown vectors. | Assigned (20160112) | None (candidate not yet proposed) | View | |
34753 | CVE-2008-4636 | Candidate | yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process. | Assigned (20081021) | None (candidate not yet proposed) | View | |
53670 | CVE-2012-0427 | Candidate | yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain privileges via a crafted (1) file name or (2) directory name. | Assigned (20120109) | None (candidate not yet proposed) | View |
Page 43 of 20943, showing 5 records out of 104715 total, starting on record 211, ending on 215