CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70134  CVE-2014-2839  Candidate  SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rating-stats page to wp-admin/admin.php.  Assigned (20140410)  None (candidate not yet proposed)    View
70390  CVE-2014-3095  Candidate  The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.  Assigned (20140429)  None (candidate not yet proposed)    View
70646  CVE-2014-3350  Candidate  Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCuh84870.  Assigned (20140507)  None (candidate not yet proposed)    View
70902  CVE-2014-3606  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140514)  None (candidate not yet proposed)    View
71158  CVE-2014-3862  Candidate  CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.  Assigned (20140525)  None (candidate not yet proposed)    View

Page 19017 of 20943, showing 5 records out of 104715 total, starting on record 95081, ending on 95085

Actions