CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67085  CVE-2013-7138  Candidate  Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.  Assigned (20131218)  None (candidate not yet proposed)    View
67341  CVE-2013-7394  Candidate  The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types.  Assigned (20140807)  None (candidate not yet proposed)    View
2061  CVE-2000-0483  Entry  The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.        View
67597  CVE-2014-0188  Candidate  The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.  Assigned (20131203)  None (candidate not yet proposed)    View
2317  CVE-2000-0741  Entry  Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.        View

Page 1051 of 20943, showing 5 records out of 104715 total, starting on record 5251, ending on 5255

Actions