CVE List

Id CVE No. Status Description Phase Votes Comments Actions
66426  CVE-2013-6479  Candidate  util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response.  Assigned (20131104)  None (candidate not yet proposed)    View
15622  CVE-2005-4418  Candidate  util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.  Assigned (20051220)  None (candidate not yet proposed)    View
61760  CVE-2013-1813  Candidate  util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.  Assigned (20130219)  None (candidate not yet proposed)    View
8661  CVE-2004-0233  Candidate  Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.  Assigned (20040317)  None (candidate not yet proposed)    View
3291  CVE-2001-0474  Entry  Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.        View

Page 581 of 20943, showing 5 records out of 104715 total, starting on record 2901, ending on 2905

Actions