CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
17512 | CVE-2006-1408 | Candidate | Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet from the socket. | Assigned (20060328) | None (candidate not yet proposed) | View | |
67239 | CVE-2013-7292 | Candidate | VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password. | Assigned (20140113) | None (candidate not yet proposed) | View | |
18806 | CVE-2006-2702 | Candidate | vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER["REMOTE_ADDR"]. | Assigned (20060530) | None (candidate not yet proposed) | View | |
64431 | CVE-2013-4484 | Candidate | Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI. | Assigned (20130612) | None (candidate not yet proposed) | View | |
86129 | CVE-2015-8852 | Candidate | Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request. | Assigned (20160418) | None (candidate not yet proposed) | View |
Page 568 of 20943, showing 5 records out of 104715 total, starting on record 2836, ending on 2840