CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69904  CVE-2014-2609  Candidate  The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.  Assigned (20140324)  None (candidate not yet proposed)    View
4624  CVE-2002-0232  Candidate  Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
70160  CVE-2014-2865  Candidate  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a "" character, as demonstrated by using this character within a pathname on the drive containing the web root directory of a ColdFusion installation.  Assigned (20140415)  None (candidate not yet proposed)    View
70416  CVE-2014-3121  Candidate  rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.  Assigned (20140429)  None (candidate not yet proposed)    View
5136  CVE-2002-0746  Candidate  Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.  Proposed (20020726)  ACCEPT(3) Baker, Bollinger, Cole | NOOP(4) Armstrong, Cox, Foat, Wall    View

Page 1890 of 20943, showing 5 records out of 104715 total, starting on record 9446, ending on 9450

Actions