CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67560  CVE-2014-0151  Candidate  Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.  Assigned (20131203)  None (candidate not yet proposed)    View
67816  CVE-2014-0407  Candidate  Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0405.  Assigned (20131212)  None (candidate not yet proposed)    View
68072  CVE-2014-0663  Candidate  Cross-site scripting (XSS) vulnerability in the web framework in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCum03625.  Assigned (20140102)  None (candidate not yet proposed)    View
2792  CVE-2000-1225  Candidate  Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.  Assigned (20050621)  None (candidate not yet proposed)    View
68328  CVE-2014-0919  Candidate  IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.  Assigned (20140106)  None (candidate not yet proposed)    View

Page 19058 of 20943, showing 5 records out of 104715 total, starting on record 95286, ending on 95290

Actions