CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
71911 | CVE-2014-4614 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrators for requests that use the (1) pwg.groups.addUser, (2) pwg.groups.deleteUser, (3) pwg.groups.setInfo, (4) pwg.users.setInfo, (5) pwg.permissions.add, or (6) pwg.permissions.remove method. | Assigned (20140624) | None (candidate not yet proposed) | View | |
6631 | CVE-2002-2249 | Candidate | PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php. | Assigned (20071014) | None (candidate not yet proposed) | View | |
72167 | CVE-2014-4870 | Candidate | /opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration. | Assigned (20140710) | None (candidate not yet proposed) | View | |
72423 | CVE-2014-5126 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20140730) | None (candidate not yet proposed) | View | |
7143 | CVE-2003-0315 | Candidate | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow. | Assigned (20030516) | None (candidate not yet proposed) | View |
Page 18985 of 20943, showing 5 records out of 104715 total, starting on record 94921, ending on 94925