CVE List

Id CVE No. Status Description Phase Votes Comments Actions
522  CVE-1999-0525  Candidate  IP traceroute is allowed from arbitrary hosts.  Proposed (19990726)  MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Northcutt  Frech> XF:traceroute  View
66058  CVE-2013-6111  Candidate  Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.x, 1.0.22.7, 1.1.x, 1.24.1, 1.3.25.1 through 1.3.25.4, 1.4.26.1 through 1.4.26.4, 1.5.27.1 through 1.5.27.3, and 1.6.29.1 through 1.6.29.6 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20131012)  None (candidate not yet proposed)    View
778  CVE-1999-0798  Candidate  Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.  Proposed (19991222)  ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(1) Frech | NOOP(1) Christey  Christey> Is CVE-1999-0389 a duplicate of CVE-1999-0798? CVE-1999-0389 | has January 1999 dates associated with it, while CVE-1999-0798 | was reported in late December. | | http://marc.theaimsgroup.com/?l=bugtraq&m=91278867118128&w=2 | | SCO appears to have acknowledged this as well: | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.01a | | The poster also claims that OpenBSD fixed this as well. | Frech> XF:bootp-remote-bo | Christey> Further analysis indicates that this is a duplicate of CVE-1999-0799 | CHANGE> [Christey changed vote from REJECT to NOOP] | Christey> What was I thinking? Brian Caswell pointed out that this is | *not* the same bug as CVE-1999-0799. As reported in the | 1998 Bugtraq post, the bug is in bootpd.c, and is related | to providing an htype value that is used as an index | into an array, and exceeds the intended boundaries of that | array.  View
66314  CVE-2013-6367  Candidate  The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.  Assigned (20131104)  None (candidate not yet proposed)    View
1034  CVE-1999-1054  Candidate  The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.  Proposed (20010912)  ACCEPT(1) Cole | NOOP(2) Foat, Wall    View

Page 800 of 20943, showing 5 records out of 104715 total, starting on record 3996, ending on 4000

Actions