CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4879  CVE-2002-0487  Candidate  Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser"s cache.  Proposed (20020611)  ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
70415  CVE-2014-3120  Candidate  The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor"s intended security policy if the user does not run Elasticsearch in its own independent virtual machine.  Assigned (20140429)  None (candidate not yet proposed)    View
70671  CVE-2014-3375  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90597.  Assigned (20140507)  None (candidate not yet proposed)    View
5391  CVE-2002-1003  Candidate  Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
70927  CVE-2014-3631  Candidate  The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation.  Assigned (20140514)  None (candidate not yet proposed)    View

Page 1216 of 20943, showing 5 records out of 104715 total, starting on record 6076, ending on 6080

Actions