CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69134  CVE-2014-1839  Candidate  The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.  Assigned (20140202)  None (candidate not yet proposed)    View
3854  CVE-2001-1050  Candidate  CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green    View
69390  CVE-2014-2095  Candidate  Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory.  Assigned (20140224)  None (candidate not yet proposed)    View
4110  CVE-2001-1306  Candidate  iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  Frech> XF:iplanet-ldap-protos-bo(6893)  View
69646  CVE-2014-2351  Candidate  SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.  Assigned (20140313)  None (candidate not yet proposed)    View

Page 1120 of 20943, showing 5 records out of 104715 total, starting on record 5596, ending on 5600

Actions