CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
69134 | CVE-2014-1839 | Candidate | The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file. | Assigned (20140202) | None (candidate not yet proposed) | View | |
3854 | CVE-2001-1050 | Candidate | CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Proposed (20020131) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green | View | |
69390 | CVE-2014-2095 | Candidate | Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory. | Assigned (20140224) | None (candidate not yet proposed) | View | |
4110 | CVE-2001-1306 | Candidate | iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite. | Proposed (20020502) | ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat | Frech> XF:iplanet-ldap-protos-bo(6893) | View |
69646 | CVE-2014-2351 | Candidate | SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests. | Assigned (20140313) | None (candidate not yet proposed) | View |
Page 1120 of 20943, showing 5 records out of 104715 total, starting on record 5596, ending on 5600