CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7917  CVE-2003-1093  Candidate  BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user"s password when it throws a ResourceAllocationException.  Assigned (20050310)  None (candidate not yet proposed)    View
73453  CVE-2014-6154  Candidate  Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a .. (dot dot) in a URL.  Assigned (20140902)  None (candidate not yet proposed)    View
8173  CVE-2003-1349  Candidate  Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a ".." (backslash dot dot) in the CD (CWD) command.  Assigned (20071014)  None (candidate not yet proposed)    View
73709  CVE-2014-6409  Candidate  Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update.  Assigned (20140915)  None (candidate not yet proposed)    View
73965  CVE-2014-6665  Candidate  The Ahmed Bukhatir Nasheeds TV (aka com.wAhmedBukhatirApp) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 18832 of 20943, showing 5 records out of 104715 total, starting on record 94156, ending on 94160

Actions