CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
23443 | CVE-2007-0086 | Candidate | ** DISPUTED ** The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal. | Assigned (20070105) | None (candidate not yet proposed) | View | |
31363 | CVE-2008-1246 | Candidate | ** DISPUTED ** The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. NOTE: third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank. | Assigned (20080310) | None (candidate not yet proposed) | View | |
15718 | CVE-2005-4514 | Candidate | ** DISPUTED ** The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious tokens, which allows attackers to bypass script detection by using tokens that can be upper or lower case. NOTE: the vendor has stated that this problem could not be reproduced, and has asked the researcher for more information, without a response as of 20060103. | Assigned (20051222) | None (candidate not yet proposed) | View | |
25222 | CVE-2007-1865 | Candidate | ** DISPUTED ** The ipv6_getsockopt_sticky function in the kernel in Red Hat Enterprise Linux (RHEL) Beta 5.1.0 allows local users to obtain sensitive information (kernel memory contents) via a negative value of the len parameter. NOTE: this issue has been disputed in a bug comment, stating that "len is ignored when copying header info to the user"s buffer." | Assigned (20070404) | None (candidate not yet proposed) | View | |
8131 | CVE-2003-1307 | Candidate | ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server"s process group and use the server"s file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server"s TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP." | Assigned (20061023) | None (candidate not yet proposed) | View |
Page 66 of 20943, showing 5 records out of 104715 total, starting on record 326, ending on 330