CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
45971 | CVE-2010-3387 | Candidate | ** DISPUTED ** vdrleaktest in Video Disk Recorder (VDR) 1.6.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: a third party disputes this issue because the script erroneously uses a semicolon in a context where a colon was intended. | Assigned (20100915) | None (candidate not yet proposed) | View | |
23740 | CVE-2007-0383 | Candidate | ** DISPUTED ** WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact. NOTE: The researcher reports that the vendor response was "this is not a security bug." | Assigned (20070119) | None (candidate not yet proposed) | View | |
42431 | CVE-2009-4996 | Candidate | ** DISPUTED ** Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments. | Assigned (20100907) | None (candidate not yet proposed) | View | |
11139 | CVE-2004-2713 | Candidate | ** DISPUTED ** Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%Internet Logs* to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder contents or permissions. NOTE: this issue has been disputed by the vendor, who claims that it does not affect product functionality since the same information is also saved in a protected file. | Assigned (20071006) | None (candidate not yet proposed) | View | |
48649 | CVE-2011-0737 | Candidate | ** DISPUTED ** Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure. | Assigned (20110201) | None (candidate not yet proposed) | View |
Page 70 of 20943, showing 5 records out of 104715 total, starting on record 346, ending on 350