CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69648  CVE-2014-2353  Candidate  Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140313)  None (candidate not yet proposed)    View
4368  CVE-2001-1568  Candidate  CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.  Assigned (20050714)  None (candidate not yet proposed)    View
69904  CVE-2014-2609  Candidate  The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.  Assigned (20140324)  None (candidate not yet proposed)    View
4624  CVE-2002-0232  Candidate  Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
70160  CVE-2014-2865  Candidate  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a "" character, as demonstrated by using this character within a pathname on the drive containing the web root directory of a ColdFusion installation.  Assigned (20140415)  None (candidate not yet proposed)    View

Page 1279 of 20943, showing 5 records out of 104715 total, starting on record 6391, ending on 6395

Actions