CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1809  CVE-2000-0231  Entry  Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.        View
67345  CVE-2013-7398  Candidate  main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.  Assigned (20140825)  None (candidate not yet proposed)    View
67601  CVE-2014-0192  Candidate  Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."  Assigned (20131203)  None (candidate not yet proposed)    View
2321  CVE-2000-0745  Entry  admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.        View
67857  CVE-2014-0448  Candidate  Unspecified vulnerability in Oracle Java SE 7u51 and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.  Assigned (20131212)  None (candidate not yet proposed)    View

Page 1373 of 20943, showing 5 records out of 104715 total, starting on record 6861, ending on 6865

Actions