CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70168  CVE-2014-2873  Candidate  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obtain sensitive server information by using a predictable name in a request for a file.  Assigned (20140415)  None (candidate not yet proposed)    View
70424  CVE-2014-3129  Candidate  The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted request, related to SAP Solution Manager 7.1.  Assigned (20140430)  None (candidate not yet proposed)    View
70680  CVE-2014-3384  Candidate  The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted packet that is sent during tunnel creation, aka Bug ID CSCum96401.  Assigned (20140507)  None (candidate not yet proposed)    View
70936  CVE-2014-3640  Candidate  The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.  Assigned (20140514)  None (candidate not yet proposed)    View
71192  CVE-2014-3896  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.  Assigned (20140527)  None (candidate not yet proposed)    View

Page 1890 of 20943, showing 5 records out of 104715 total, starting on record 9446, ending on 9450

Actions