CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17512  CVE-2006-1408  Candidate  Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet from the socket.  Assigned (20060328)  None (candidate not yet proposed)    View
67239  CVE-2013-7292  Candidate  VASCO IDENTIKEY Authentication Server (IAS) 3.4.x allows remote authenticated users to bypass Active Directory (AD) authentication by entering only a DIGIPASS one-time password, instead of the intended combination of this one-time password and a multiple-time AD password.  Assigned (20140113)  None (candidate not yet proposed)    View
18806  CVE-2006-2702  Candidate  vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER["REMOTE_ADDR"].  Assigned (20060530)  None (candidate not yet proposed)    View
64431  CVE-2013-4484  Candidate  Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.  Assigned (20130612)  None (candidate not yet proposed)    View
86129  CVE-2015-8852  Candidate  Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.  Assigned (20160418)  None (candidate not yet proposed)    View

Page 568 of 20943, showing 5 records out of 104715 total, starting on record 2836, ending on 2840

Actions