CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
65801 | CVE-2013-5854 | Candidate | Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors. | Assigned (20130918) | None (candidate not yet proposed) | View | |
521 | CVE-1999-0524 | Candidate | ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. | Modified (20161206) | MODIFY(3) Baker, Frech, Meunier | REJECT(1) Northcutt | Frech> XF:icmp-timestamp | XF:icmp-netmask | Meunier> If this is not merged with 1999-0523 as I commented for that | CVE, then the description should be changed to "ICMP messages of types | 13 and 14 (timestamp request and reply) and 17 and 18 (netmask request | and reply) are acted upon without any access control". It"s a more | precise and correct language. I believe that this is a valid CVE | entry (it"s a common source of vulnerabilities or exposures) even | though I see that the inferred action was "reject". Knowing the time | of a host also allows attacks against random number generators that | are seeded with the current time. I want to push to have it accepted. | Baker> I agree with the description changes suggested by Pascal | View |
66057 | CVE-2013-6110 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20131012) | None (candidate not yet proposed) | View | |
66313 | CVE-2013-6366 | Candidate | The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call. | Assigned (20131104) | None (candidate not yet proposed) | View | |
1033 | CVE-1999-1053 | Candidate | guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:guestbook-cgi-command-execution(7783) | View |
Page 1331 of 20943, showing 5 records out of 104715 total, starting on record 6651, ending on 6655