CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67299  CVE-2013-7352  Candidate  Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.  Assigned (20140402)  None (candidate not yet proposed)    View
67555  CVE-2014-0146  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20131203)  None (candidate not yet proposed)    View
67811  CVE-2014-0402  Candidate  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.  Assigned (20131212)  None (candidate not yet proposed)    View
68067  CVE-2014-0658  Candidate  Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898.  Assigned (20140102)  None (candidate not yet proposed)    View
2787  CVE-2000-1220  Candidate  The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.  Assigned (20050421)  None (candidate not yet proposed)    View

Page 18672 of 20943, showing 5 records out of 104715 total, starting on record 93356, ending on 93360

Actions