CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
69350 | CVE-2014-2055 | Candidate | SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack. | Assigned (20140219) | None (candidate not yet proposed) | View | |
4070 | CVE-2001-1266 | Entry | Directory traversal vulnerability in Doug Neal"s HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code "%2E". | View | |||
69606 | CVE-2014-2311 | Candidate | SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Assigned (20140306) | None (candidate not yet proposed) | View | |
4326 | CVE-2001-1526 | Candidate | Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter. | Assigned (20050714) | None (candidate not yet proposed) | View | |
69862 | CVE-2014-2567 | Candidate | The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command. | Assigned (20140320) | None (candidate not yet proposed) | View |
Page 18864 of 20943, showing 5 records out of 104715 total, starting on record 94316, ending on 94320