CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1809 | CVE-2000-0231 | Entry | Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges. | View | |||
67345 | CVE-2013-7398 | Candidate | main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate. | Assigned (20140825) | None (candidate not yet proposed) | View | |
67601 | CVE-2014-0192 | Candidate | Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof." | Assigned (20131203) | None (candidate not yet proposed) | View | |
2321 | CVE-2000-0745 | Entry | admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter. | View | |||
67857 | CVE-2014-0448 | Candidate | Unspecified vulnerability in Oracle Java SE 7u51 and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. | Assigned (20131212) | None (candidate not yet proposed) | View |
Page 1373 of 20943, showing 5 records out of 104715 total, starting on record 6861, ending on 6865