CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7917 | CVE-2003-1093 | Candidate | BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user"s password when it throws a ResourceAllocationException. | Assigned (20050310) | None (candidate not yet proposed) | View | |
73453 | CVE-2014-6154 | Candidate | Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a .. (dot dot) in a URL. | Assigned (20140902) | None (candidate not yet proposed) | View | |
8173 | CVE-2003-1349 | Candidate | Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a ".." (backslash dot dot) in the CD (CWD) command. | Assigned (20071014) | None (candidate not yet proposed) | View | |
73709 | CVE-2014-6409 | Candidate | Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update. | Assigned (20140915) | None (candidate not yet proposed) | View | |
73965 | CVE-2014-6665 | Candidate | The Ahmed Bukhatir Nasheeds TV (aka com.wAhmedBukhatirApp) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20140919) | None (candidate not yet proposed) | View |
Page 18832 of 20943, showing 5 records out of 104715 total, starting on record 94156, ending on 94160