CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67563 | CVE-2014-0154 | Candidate | oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | Assigned (20131203) | None (candidate not yet proposed) | View | |
67819 | CVE-2014-0410 | Candidate | Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424. | Assigned (20131212) | None (candidate not yet proposed) | View | |
68075 | CVE-2014-0666 | Candidate | Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056. | Assigned (20140102) | None (candidate not yet proposed) | View | |
2795 | CVE-2000-1228 | Candidate | Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables. | Assigned (20050714) | None (candidate not yet proposed) | View | |
68331 | CVE-2014-0922 | Candidate | IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data. | Assigned (20140106) | None (candidate not yet proposed) | View |
Page 18665 of 20943, showing 5 records out of 104715 total, starting on record 93321, ending on 93325