CVE List

Id CVE No. Status Description Phase Votes Comments Actions
45971  CVE-2010-3387  Candidate  ** DISPUTED ** vdrleaktest in Video Disk Recorder (VDR) 1.6.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: a third party disputes this issue because the script erroneously uses a semicolon in a context where a colon was intended.  Assigned (20100915)  None (candidate not yet proposed)    View
23740  CVE-2007-0383  Candidate  ** DISPUTED ** WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact. NOTE: The researcher reports that the vendor response was "this is not a security bug."  Assigned (20070119)  None (candidate not yet proposed)    View
42431  CVE-2009-4996  Candidate  ** DISPUTED ** Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.  Assigned (20100907)  None (candidate not yet proposed)    View
11139  CVE-2004-2713  Candidate  ** DISPUTED ** Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%Internet Logs* to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder contents or permissions. NOTE: this issue has been disputed by the vendor, who claims that it does not affect product functionality since the same information is also saved in a protected file.  Assigned (20071006)  None (candidate not yet proposed)    View
48649  CVE-2011-0737  Candidate  ** DISPUTED ** Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure.  Assigned (20110201)  None (candidate not yet proposed)    View

Page 70 of 20943, showing 5 records out of 104715 total, starting on record 346, ending on 350

Actions