CVE List

Id CVE No. Status Description Phase Votes Comments Actions
65801  CVE-2013-5854  Candidate  Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors.  Assigned (20130918)  None (candidate not yet proposed)    View
521  CVE-1999-0524  Candidate  ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.  Modified (20161206)  MODIFY(3) Baker, Frech, Meunier | REJECT(1) Northcutt  Frech> XF:icmp-timestamp | XF:icmp-netmask | Meunier> If this is not merged with 1999-0523 as I commented for that | CVE, then the description should be changed to "ICMP messages of types | 13 and 14 (timestamp request and reply) and 17 and 18 (netmask request | and reply) are acted upon without any access control". It"s a more | precise and correct language. I believe that this is a valid CVE | entry (it"s a common source of vulnerabilities or exposures) even | though I see that the inferred action was "reject". Knowing the time | of a host also allows attacks against random number generators that | are seeded with the current time. I want to push to have it accepted. | Baker> I agree with the description changes suggested by Pascal  View
66057  CVE-2013-6110  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20131012)  None (candidate not yet proposed)    View
66313  CVE-2013-6366  Candidate  The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.  Assigned (20131104)  None (candidate not yet proposed)    View
1033  CVE-1999-1053  Candidate  guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:guestbook-cgi-command-execution(7783)  View

Page 1331 of 20943, showing 5 records out of 104715 total, starting on record 6651, ending on 6655

Actions