CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76039  CVE-2014-8738  Candidate  The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.  Assigned (20141113)  None (candidate not yet proposed)    View
10759  CVE-2004-2333  Candidate  Bodington 2.1.0 RC1 and earlier does not secure the file upload area, which allows remote attackers to read uploaded files.  Assigned (20050816)  None (candidate not yet proposed)    View
76295  CVE-2014-8994  Candidate  The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).  Assigned (20141119)  None (candidate not yet proposed)    View
11015  CVE-2004-2589  Candidate  Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length header, which causes Gaim to abort when attempting to allocate memory.  Assigned (20051128)  None (candidate not yet proposed)    View
76551  CVE-2014-9250  Candidate  Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this cookie, aka ZEN-10418.  Assigned (20141203)  None (candidate not yet proposed)    View

Page 580 of 20943, showing 5 records out of 104715 total, starting on record 2896, ending on 2900

Actions