CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67049  CVE-2013-7102  Candidate  Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/admin/ in the OptimizePress theme before 1.61 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images_comingsoon, images_lncthumbs, or images_optbuttons in wp-content/uploads/optpress/, as exploited in the wild in November 2013.  Assigned (20131214)  None (candidate not yet proposed)    View
67305  CVE-2013-7358  Candidate  Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other identity information via unknown vectors.  Assigned (20140410)  None (candidate not yet proposed)    View
67561  CVE-2014-0152  Candidate  Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.  Assigned (20131203)  None (candidate not yet proposed)    View
67817  CVE-2014-0408  Candidate  Unspecified vulnerability in Oracle Java SE 7u45, when running on OS X, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.  Assigned (20131212)  None (candidate not yet proposed)    View
68073  CVE-2014-0664  Candidate  The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) via unspecified IMAP commands, aka Bug ID CSCul49976.  Assigned (20140102)  None (candidate not yet proposed)    View

Page 19115 of 20943, showing 5 records out of 104715 total, starting on record 95571, ending on 95575

Actions