CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70120  CVE-2014-2825  Candidate  Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.  Assigned (20140410)  None (candidate not yet proposed)    View
4840  CVE-2002-0448  Candidate  Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
70376  CVE-2014-3081  Candidate  prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.  Assigned (20140429)  None (candidate not yet proposed)    View
5096  CVE-2002-0706  Candidate  UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.  Modified (20050610)  ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall    View
70632  CVE-2014-3336  Candidate  SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016.  Assigned (20140507)  None (candidate not yet proposed)    View

Page 19026 of 20943, showing 5 records out of 104715 total, starting on record 95126, ending on 95130

Actions