CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67560 | CVE-2014-0151 | Candidate | Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request. | Assigned (20131203) | None (candidate not yet proposed) | View | |
67816 | CVE-2014-0407 | Candidate | Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405. | Assigned (20131212) | None (candidate not yet proposed) | View | |
68072 | CVE-2014-0663 | Candidate | Cross-site scripting (XSS) vulnerability in the web framework in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCum03625. | Assigned (20140102) | None (candidate not yet proposed) | View | |
2792 | CVE-2000-1225 | Candidate | Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program. | Assigned (20050621) | None (candidate not yet proposed) | View | |
68328 | CVE-2014-0919 | Candidate | IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities. | Assigned (20140106) | None (candidate not yet proposed) | View |
Page 19058 of 20943, showing 5 records out of 104715 total, starting on record 95286, ending on 95290