CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4076  CVE-2001-1272  Candidate  wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.  Proposed (20020502)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
69612  CVE-2014-2317  Candidate  SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information.  Assigned (20140307)  None (candidate not yet proposed)    View
4332  CVE-2001-1532  Candidate  WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.  Assigned (20050714)  None (candidate not yet proposed)    View
69868  CVE-2014-2573  Candidate  The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.  Assigned (20140321)  None (candidate not yet proposed)    View
70124  CVE-2014-2829  Candidate  Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.  Assigned (20140410)  None (candidate not yet proposed)    View

Page 18747 of 20943, showing 5 records out of 104715 total, starting on record 93731, ending on 93735

Actions