CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67563  CVE-2014-0154  Candidate  oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.  Assigned (20131203)  None (candidate not yet proposed)    View
67819  CVE-2014-0410  Candidate  Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.  Assigned (20131212)  None (candidate not yet proposed)    View
68075  CVE-2014-0666  Candidate  Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056.  Assigned (20140102)  None (candidate not yet proposed)    View
2795  CVE-2000-1228  Candidate  Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.  Assigned (20050714)  None (candidate not yet proposed)    View
68331  CVE-2014-0922  Candidate  IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data.  Assigned (20140106)  None (candidate not yet proposed)    View

Page 18665 of 20943, showing 5 records out of 104715 total, starting on record 93321, ending on 93325

Actions