CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68879  CVE-2014-1584  Candidate  The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 skips pinning checks upon an unspecified issuer-verification error, which makes it easier for remote attackers to bypass an intended pinning configuration and spoof a web site via a crafted certificate that leads to presentation of the Untrusted Connection dialog to the user.  Assigned (20140116)  None (candidate not yet proposed)    View
69135  CVE-2014-1840  Candidate  Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.  Assigned (20140202)  None (candidate not yet proposed)    View
69391  CVE-2014-2096  Candidate  Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0 allows local users to gain privileges via a Trojan horse bin/catfish.py under the current working directory.  Assigned (20140224)  None (candidate not yet proposed)    View
69647  CVE-2014-2352  Candidate  Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname.  Assigned (20140313)  None (candidate not yet proposed)    View
4367  CVE-2001-1567  Candidate  Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 1196 of 20943, showing 5 records out of 104715 total, starting on record 5976, ending on 5980

Actions