CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70157  CVE-2014-2862  Candidate  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors.  Assigned (20140415)  None (candidate not yet proposed)    View
4877  CVE-2002-0485  Candidate  Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.  Modified (20040811)  ACCEPT(1) Prosser | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nav-case-bypass-protection(9860) | Prosser> This issues was a continuation of an earlier reported issue | with non-RFC compliant MIME headers. The discover was testing a | non-updated version of NAV 2002 which was vulnerable to this and other | non-RFC compliant configurations. Updated and current releases are not | vulnerable to this problem | | http://securityresponse.symantec.com/avcenter/security/Content/2002.04.03.html | is the posted response to this issue.  View
70413  CVE-2014-3118  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140429)  None (candidate not yet proposed)    View
5133  CVE-2002-0743  Candidate  mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.  Proposed (20020726)  ACCEPT(3) Baker, Bollinger, Cole | NOOP(4) Armstrong, Cox, Foat, Wall  Bollinger> IY29516 is the AIX 4.3 APAR for a variety of buffer | overflows in mail and mailx found during internal testing. (AIX 5.1 | APAR IY28170 needs to be added to the References.) I don"t know if | this is similar to CVE-2002-0041 or not due to the vague description | in the associated advisory. One of the overflows fixed is similar to | CVE-2001-0565, but CVE-2000-0545 does not apply here.  View
70669  CVE-2014-3373  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed Number Analyzer interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCup92550.  Assigned (20140507)  None (candidate not yet proposed)    View

Page 1042 of 20943, showing 5 records out of 104715 total, starting on record 5206, ending on 5210

Actions