CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70382 | CVE-2014-3087 | Candidate | callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | Assigned (20140429) | None (candidate not yet proposed) | View | |
5102 | CVE-2002-0712 | Candidate | Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations. | Assigned (20020719) | None (candidate not yet proposed) | View | |
70638 | CVE-2014-3342 | Candidate | The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka Bug IDs CSCuq42336, CSCuq76853, CSCuq76873, and CSCuq45383. | Assigned (20140507) | None (candidate not yet proposed) | View | |
5358 | CVE-2002-0970 | Entry | The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack. | View | |||
70894 | CVE-2014-3598 | Candidate | The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image. | Assigned (20140514) | None (candidate not yet proposed) | View |
Page 19137 of 20943, showing 5 records out of 104715 total, starting on record 95681, ending on 95685