CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10664  CVE-2004-2238  Candidate  ** DISPUTED ** Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability.  Assigned (20050717)  None (candidate not yet proposed)    View
35067  CVE-2008-4950  Candidate  ** DISPUTED ** gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this vulnerability, stating that "There is no sense in this bug - the script ... is called under specific cross-building environments within a chroot."  Assigned (20081105)  None (candidate not yet proposed)    View
53282  CVE-2012-0039  Candidate  ** DISPUTED ** GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.  Assigned (20111207)  None (candidate not yet proposed)    View
46585  CVE-2010-4001  Candidate  ** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.  Assigned (20101019)  None (candidate not yet proposed)    View
77069  CVE-2014-9768  Candidate  ** DISPUTED ** IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor"s perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability.  Assigned (20160317)  None (candidate not yet proposed)    View

Page 75 of 20943, showing 5 records out of 104715 total, starting on record 371, ending on 375

Actions