CVE List

Id CVE No. Status Description Phase Votes Comments Actions
69353  CVE-2014-2058  Candidate  BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7330.  Assigned (20140219)  None (candidate not yet proposed)    View
69609  CVE-2014-2314  Candidate  Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.  Assigned (20140307)  None (candidate not yet proposed)    View
4329  CVE-2001-1529  Candidate  Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string. NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.  Assigned (20050714)  None (candidate not yet proposed)    View
69865  CVE-2014-2570  Candidate  Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP Font Lib before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.  Assigned (20140320)  None (candidate not yet proposed)    View
4585  CVE-2002-0193  Entry  Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.        View

Page 19106 of 20943, showing 5 records out of 104715 total, starting on record 95526, ending on 95530

Actions