CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73453  CVE-2014-6154  Candidate  Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a .. (dot dot) in a URL.  Assigned (20140902)  None (candidate not yet proposed)    View
8173  CVE-2003-1349  Candidate  Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a ".." (backslash dot dot) in the CD (CWD) command.  Assigned (20071014)  None (candidate not yet proposed)    View
73709  CVE-2014-6409  Candidate  Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update.  Assigned (20140915)  None (candidate not yet proposed)    View
8429  CVE-2004-0001  Entry  Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.        View
73965  CVE-2014-6665  Candidate  The Ahmed Bukhatir Nasheeds TV (aka com.wAhmedBukhatirApp) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View

Page 19061 of 20943, showing 5 records out of 104715 total, starting on record 95301, ending on 95305

Actions