CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69904  CVE-2014-2609  Candidate  The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.  Assigned (20140324)  None (candidate not yet proposed)    View
70160  CVE-2014-2865  Candidate  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a "" character, as demonstrated by using this character within a pathname on the drive containing the web root directory of a ColdFusion installation.  Assigned (20140415)  None (candidate not yet proposed)    View
70416  CVE-2014-3121  Candidate  rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.  Assigned (20140429)  None (candidate not yet proposed)    View
70672  CVE-2014-3376  Candidate  Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed RSVP packet, aka Bug ID CSCuq12031.  Assigned (20140507)  None (candidate not yet proposed)    View
70928  CVE-2014-3632  Candidate  The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a CVE-2013-6433 regression.  Assigned (20140514)  None (candidate not yet proposed)    View

Page 1274 of 20943, showing 5 records out of 104715 total, starting on record 6366, ending on 6370

Actions