69648 |
CVE-2014-2353 |
Candidate |
Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Assigned (20140313) |
None (candidate not yet proposed) |
|
View
|
4368 |
CVE-2001-1568 |
Candidate |
CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack. |
Assigned (20050714) |
None (candidate not yet proposed) |
|
View
|
69904 |
CVE-2014-2609 |
Candidate |
The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116. |
Assigned (20140324) |
None (candidate not yet proposed) |
|
View
|
4624 |
CVE-2002-0232 |
Candidate |
Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi. |
Proposed (20020502) |
ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall |
|
View
|
70160 |
CVE-2014-2865 |
Candidate |
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a " |