NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
14078 | CVE-2010-2629 | The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote attackers to conduct HTTP request smuggling attacks and possibly bypass intended header insertions via crafted header data, as demonstrated by an LF character between the ClientCert-Subject and ClientCert-Subject-CN headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1576. | 2 | 7.5 | High | 2017-01-18 | 2010-07-07 | View | |
79614 | CVE-2002-0609 | Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
14334 | CVE-2010-2903 | Google Chrome before 5.0.375.125 performs unexpected truncation and improper eliding of hostnames, which has unspecified impact and remote attack vectors. | 2 | 10 | High | 2017-01-18 | 2011-07-18 | View | |
79870 | CVE-2002-0872 | l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
14590 | CVE-2010-3172 | CRLF injection vulnerability in Bugzilla before 3.2.9, 3.4.x before 3.4.9, 3.6.x before 3.6.3, and 4.0.x before 4.0rc1, when Server Push is enabled in a web browser, allows remote attackers to inject arbitrary HTTP headers and content, and conduct HTTP response splitting attacks, via a crafted URL. | 2 | 2.6 | Low | 2017-01-18 | 2010-12-16 | View |
Page 17571 of 17672, showing 5 records out of 88360 total, starting on record 87851, ending on 87855