CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69136  CVE-2014-1841  Candidate  Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user"s home folder via a Move action with a .. (dot dot) in the src parameter.  Assigned (20140202)  None (candidate not yet proposed)    View
3856  CVE-2001-1052  Candidate  Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall    View
69392  CVE-2014-2097  Candidate  The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted TAK (aka Tom"s lossless Audio Kompressor) data.  Assigned (20140224)  None (candidate not yet proposed)    View
4112  CVE-2001-1308  Candidate  Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Proposed (20020502)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
69648  CVE-2014-2353  Candidate  Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20140313)  None (candidate not yet proposed)    View

Page 1295 of 20943, showing 5 records out of 104715 total, starting on record 6471, ending on 6475

Actions