CVE List

Id CVE No. Status Description Phase Votes Comments Actions
68868  CVE-2014-1573  Candidate  Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.  Assigned (20140116)  None (candidate not yet proposed)    View
69124  CVE-2014-1829  Candidate  Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.  Assigned (20140130)  None (candidate not yet proposed)    View
69380  CVE-2014-2085  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2084. Reason: This issue was MERGED into CVE-2014-2084 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2014-2084 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20140219)  None (candidate not yet proposed)    View
69636  CVE-2014-2341  Candidate  Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.  Assigned (20140312)  None (candidate not yet proposed)    View
4356  CVE-2001-1556  Candidate  The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 1473 of 20943, showing 5 records out of 104715 total, starting on record 7361, ending on 7365

Actions