CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69350  CVE-2014-2055  Candidate  SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.  Assigned (20140219)  None (candidate not yet proposed)    View
4070  CVE-2001-1266  Entry  Directory traversal vulnerability in Doug Neal"s HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code "%2E".        View
69606  CVE-2014-2311  Candidate  SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20140306)  None (candidate not yet proposed)    View
4326  CVE-2001-1526  Candidate  Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.  Assigned (20050714)  None (candidate not yet proposed)    View
69862  CVE-2014-2567  Candidate  The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.  Assigned (20140320)  None (candidate not yet proposed)    View

Page 18864 of 20943, showing 5 records out of 104715 total, starting on record 94316, ending on 94320

Actions