CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67085  CVE-2013-7138  Candidate  Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.  Assigned (20131218)  None (candidate not yet proposed)    View
67341  CVE-2013-7394  Candidate  The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types.  Assigned (20140807)  None (candidate not yet proposed)    View
67597  CVE-2014-0188  Candidate  The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.  Assigned (20131203)  None (candidate not yet proposed)    View
67853  CVE-2014-0444  Candidate  Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vulnerability than CVE-2013-5868 and CVE-2013-5871.  Assigned (20131212)  None (candidate not yet proposed)    View
68109  CVE-2014-0700  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140102)  None (candidate not yet proposed)    View

Page 1041 of 20943, showing 5 records out of 104715 total, starting on record 5201, ending on 5205

Actions