CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23443  CVE-2007-0086  Candidate  ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.  Assigned (20070105)  None (candidate not yet proposed)    View
31363  CVE-2008-1246  Candidate  ** DISPUTED ** The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. NOTE: third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank.  Assigned (20080310)  None (candidate not yet proposed)    View
15718  CVE-2005-4514  Candidate  ** DISPUTED ** The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious tokens, which allows attackers to bypass script detection by using tokens that can be upper or lower case. NOTE: the vendor has stated that this problem could not be reproduced, and has asked the researcher for more information, without a response as of 20060103.  Assigned (20051222)  None (candidate not yet proposed)    View
25222  CVE-2007-1865  Candidate  ** DISPUTED ** The ipv6_getsockopt_sticky function in the kernel in Red Hat Enterprise Linux (RHEL) Beta 5.1.0 allows local users to obtain sensitive information (kernel memory contents) via a negative value of the len parameter. NOTE: this issue has been disputed in a bug comment, stating that "len is ignored when copying header info to the user"s buffer."  Assigned (20070404)  None (candidate not yet proposed)    View
8131  CVE-2003-1307  Candidate  ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server"s process group and use the server"s file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server"s TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."  Assigned (20061023)  None (candidate not yet proposed)    View

Page 66 of 20943, showing 5 records out of 104715 total, starting on record 326, ending on 330

Actions